generated: '2026-07-17' method: searched probe: true source: https://docs.paymongo.com/docs/keeping-payments-secure securityTxt: false securityTxtProbe: url: https://paymongo.com/.well-known/security.txt status: 404 contact: - mailto:security@paymongo.com bugBounty: public_program: false note: No public bug-bounty or formal published responsible-disclosure policy was found at probe time. evidence: - source: https://paymongo.com/.well-known/security.txt kind: security.txt (live probe) result: HTTP 404 - no security.txt published - source: https://docs.paymongo.com/docs/keeping-payments-secure kind: documentation note: Describes ongoing third-party vulnerability scanning and penetration testing. notes: >- As of the probe date PayMongo does not publish a /.well-known/security.txt (HTTP 404) and no public bug-bounty program was found. PayMongo states its systems undergo regular third-party vulnerability scanning and penetration testing as part of PCI DSS Level 1 compliance. Security concerns are best routed to security@paymongo.com or support@paymongo.com; verify the correct disclosure channel with PayMongo directly, as no formal published policy was located.