Report a vulnerability
Responsible Vulnerability Disclosure Policy
1. Introduction
The security of Market Pay’s information systems is a priority. This policy aims to provide a clear, secure and compliant framework for the responsible disclosure of vulnerabilities identified in our digital assets. It allows security researchers to engage with us in a structured, responsible, and collaborative manner.
2. Legal Framework
We are committed to complying with GDPR, the NIS2 Directive, the French Digital Republic Act, the Budapest Convention, as well as ISO/IEC 29147 & 30111 standards, and the recommendations of NIST, ENISA, and CISA.
3. Our Commitments
We will not pursue any legal action, either civil or criminal, against individuals who strictly adhere to this policy.
We will treat good faith reports with seriousness and respect.
We will acknowledge receipt within 48 business hours.
We will keep the researcher informed of key evaluation and resolution steps.
4. Authorized Scope
The following systems and services are covered by this policy:
- Payment Terminal
- Tap to Pay
- Online Payment
- Market Pay Hub
- Market Pay Assist
Testing outside this scope is not permitted.
5. Allowed and Prohibited Methods
✅ What you can do:
- Conduct non-intrusive testing to identify a potential flaw (e.g., XSS, SQL injection, improper access control).
- Only test your own accounts or test environments.
- Accurately document and report evidence of the vulnerability.
❌ What you must not do:
- Launch DDoS, ransomware, or brute-force attacks.
- Exploit the flaw beyond the proof of concept.
- Use social engineering or deceive users or employees.
- Access, copy, modify, or delete personal or sensitive data.
- Publicly disclose the vulnerability without our written consent.
6. How to Report
Reporting channel:
Dedicated email address: vulnerability-report@market-pay.com
Please use our PGP key:
—–BEGIN PGP PUBLIC KEY BLOCK—–
mQGNBGGlBtQBDADB7NlNXCBA1mS+1LIwzPFJ+wE00+GrDqbbnbOBUFH7akQwhAlD
qPAD3QdxyqajqKch/+8hSn708NFvl9w0w16sEV3MtomIwMG0btsgdRO/5lsx31K4
NCVUGmA6qPSLuwWEWqYgW99j4UGHYKMgwTv/x2NiBGzilUiD9DNHK/NNisoHUiB/
eY5asKXmsd3a+4OXWOzfX5dl2bCEapCp/AXTM3Ff/Hy6L4aaz+cnpIdLp4dlBV2G
fwSlUa9Lkx4tCeFhypMPdPqcnkF2TjG5DYJcJDVvYEoBIL7qtgl7GpAuQNiYZ1Bh
Tpjk0h8ZYdMZ58KqWImbOXoydN3My5jctfCigA64oQR+jJjS+PJlaM8xXSrWcDOI
+0oNZ2Mj7Oqh07utMnMszgoUiy/yjPHnUde2tJjPwcqL72nPYUi0bBZCGh0u13Y/
wn7clBN6tiC9eCVrw5/ofiEpeR+WtC5GNrZ6n4W7xKhi9x2KzdJNPojacosuH6FA
hX1FcmZ226QL7cEAEQEAAbQ6VnVsbmVyYWJpbGl0eSBSZXBvcnQgPHZ1bG5lcmFi
aWxpdHktcmVwb3J0QGRlamFtb2JpbGUuY29tPokBzgQTAQoAOBYhBN0KuaDJugTB
A5AngJCA7d9W9RMxBQJhpQbUAhsDBQsJCAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJ
EJCA7d9W9RMxwVkL/iKTHp6RUJxIZrdhM0uaiEun8erg2ZAqMpqpg8XArstJy8PQ
NW18sKlIl5QP6q0zLetL2aoMvXgS7ZRdQTdImbhCkGqTyWjbgCM3y+uo3E9PJhF5
pWSwM8W3syQSfrhFYlc4Uqqz3j9UxyiSixn8J4O75ILAtloKxukz4O3e1Xp/XebL
BhTjhwoOI02GYn8UvznoH2F0ilazgGTObhOTXSs0HBEwgooA861JpqO3lOTtXs2P
qUJtyzc0d/mQrJUZEGBZF3iwfh+giAfzhA7dVfkxkfZWvIwaIDRz/3ItY2DUVsvo
+EKQRYrSW5Ae448R3OnRmGx4SXNy3mSjQm220DXWKfL1j/rVbNYO5swKHZyJNZy1
emAoHDIEx2yO6EFDoQ8q37lOAwMdTvMG7YW4ybnsBEhPOLhvkO9YcYkQUphNCT5A
B4GZZ75Iy6g5NPqKL6sFHMxDdqUdpAJ3e2F1ljrF4oVSMBYTd2UXqboV/Zg3RhD0
8eVKugx5a7+ARBkKY7kBjQRhpQbUAQwAp7SwKrRDBXh5zEb4RMPBf+F0vJAtBPLC
wOZYel7lL4m4fvWz1LfFhDsc9voQ9DXGYHrgOjqMYe0ypiBaJCZ3nGB/I+MlqJZl
WsvoJlg5+UEqnaamY/LgTch3MluX7GYAnfVXS8VF7Dfwt5PTKA+z/xDUfGXWQOGN
srRyAs0Yx1XL/FOCSruRRayT53O08SxWaLeKsUQgIjS7yLubcJyT2Zou/kItqSzT
oEVPoZLHOHAenGAfAakkCoKJaD83vz/LWAB9Z5ctO1E8jdC2xDheiR6DFADvdHgc
MWHob4kpqVPZs6jlwN+Kbx6kcwy2XhBS0mfeNNJg2tcU96aOmJ0nQsq4hVhiC5Lf
/ru/JconjXCc39JKg+ukYxByQ0b/YHGlF8ajT9EZwJEpnZ7AZG0zmqwiErm1PkFf
KqPxAJxEPXTB0BGj0Ea3WUr0lkCwjE4XAogMHSkTnsmBS9RO5HPKqljsD628n0PJ
mLk57TT550nvvqq298GoUTwg6/IoGDpVABEBAAGJAbYEGAEKACAWIQTdCrmgyboE
wQOQJ4CQgO3fVvUTMQUCYaUG1AIbDAAKCRCQgO3fVvUTMfANC/wKYB71y0rtQ+NE
npSgYKgAf3CrvbdBkIABKexCIW/6uTz7zCMP4he4bTzmjQkvci0NpYoPFZcVWvMj
1nGp1gZLpZG2CxdA+YknfNJK55RK9LNe48GHu9Z48C18yo1Fa6HL1G2CwUorOpxG
G+9QbUrPLRreINF8EboTzCDGzZWWtLMBIbYgnlFgh3hlSRFvbIBRr2lGDvozV+O/
3FvRvbUyTI/S5e8khBTi9IT4Qqa/3ItNvB5tO0ihdXz2s0TswgIXMmS6O0Ca0Mpu
MW6QbGvT/OXhk4yyGK667+6mGWPyLblxqSZGcJw276o5D+x1YRgVEihFgxxSkwDN
zmxpolHutvdLYff2zwSELo5+NauaUwnBoKDk4TcJsclkWjVeLYVvXGu1/lpvsy2t
uH0oH3MhPU9lBl6CmoQZ4xSxcGOwORvyxN/2Soj5yZD2UcPbEvv8vg8Q6hup1STo
PHhnhlToybXS8NM809Ee2bGO5h1eeYumIay/DcoUrsnbT1MvXIU=
=vUXQ
—–END PGP PUBLIC KEY BLOCK—–
Information to include:
- Detailed description of the vulnerability
- Reproduction steps
- Affected scope
- Potential impact
- Technical data or screenshots
Report handling:
- Acknowledgement within 48 business hours
- Severity assessment based on CVSS score
- Resolution within a reasonable timeframe depending on the impact
- Ongoing communication with the researcher
7. General Conditions
No financial reward: We do not offer a bug bounty under this policy.
Confidentiality: The content of your report remains confidential. We will not disclose your identity without your consent.
Publication: We reserve the right to publish a security notice with anonymous or public credit, depending on your preferences.
8. Communication Security
- Mandatory use of HTTPS
- PGP encryption for emails
- Strong authentication for access to internal processing platforms
- Logging of all reports for audit trail
9. Legal Disclaimer
Any behavior outside the defined framework may result in legal action. This policy does not constitute authorization for intrusion.

