generated: '2026-08-26' method: searched source: https://www.payengine.co/security name: PayEngine vulnerability disclosure posture summary: >- PayEngine publishes a security overview page and names a security contact address, but it operates no formal vulnerability disclosure program. There is no responsible- or coordinated-disclosure policy, no safe-harbour statement, no bug bounty on HackerOne, Bugcrowd or Intigriti, and no security.txt on any host. A researcher who finds a flaw in a PCI DSS Level 1 payments platform has one route: the general support mailbox. security_page: url: https://www.payengine.co/security status: 200 checked: '2026-08-26' published: true contact: email: support@payengine.co channel: general support mailbox dedicated_security_address: false note: >- The security page names support@payengine.co as the security contact. It is the same address used for billing and product support, not a dedicated security alias. policy: published: false safe_harbour: false response_sla: false scope_statement: false preferred_languages: null bug_bounty: program: none platforms_checked: - HackerOne - Bugcrowd - Intigriti result: no PayEngine program found security_txt: served: false hosts_probed: - host: www.payengine.co status: 404 - host: api.payengine.co status: 400 - host: docs.payengine.co status: 404 - host: status.payengine.co status: 404 - host: console.payengine.co status: 200 result: SPA HTML shell, not a security.txt document see: well-known/payengine-well-known.yml published_practices: note: Claims made on the security page, recorded as claims, not verified by us. claims: - Full compliance with the Payment Card Industry Data Security Standard (PCI DSS) - All data transmitted to and from PayEngine is encrypted using industry-standard protocols - 24/7 monitoring for fraud detection - Regular security audits - An incident response plan with a stated commitment to transparency - Employee security training and access controls independently_verifiable: - claim: PCI DSS Level 1 Service Provider verification: >- Listed in the Visa Global Registry of Service Providers as Platform Factory, Inc. (spId 4019). See conformance/payengine-conformance.yml. trust_center: published: false note: >- No trust.payengine.co, no certification portal, and no downloadable SOC 2 / ISO 27001 report or attestation request flow. PCI DSS is the only named certification, and documentation of it is obtained through the sales/onboarding process - the docs describe forwarding a token-migration request to PayEngine so it can supply PCI L1 evidence to a prior provider. gaps: - No vulnerability disclosure policy of any kind. - No security.txt (RFC 9116) on any host. - No dedicated security contact address. - No SOC 2 or ISO 27001 certification named anywhere on the public site.