SkullPay

Security

How the platform is built to fail safe, and how to tell us when it doesn't.

Architecture in brief

Responsible disclosure

We welcome reports from security researchers. Email security@skullpay.co with enough detail to reproduce the issue. We will acknowledge within two business days, keep you informed, and credit you if you wish once a fix ships. Machine-readable contact details live at /.well-known/security.txt.

Please: test only against accounts you own (staging environments are ideal), never against merchants' live stores or real payers; do not access, modify or exfiltrate data that is not yours; avoid denial-of-service testing; give us a reasonable time to fix before public disclosure.

In scope: skullpay.co, portal.skullpay.co, pay.skullpay.co, api.skullpay.co, the WordPress plugin and the SDK. Out of scope: third-party providers, social engineering, physical attacks, and findings that require a compromised device or browser.