Security & Responsible Disclosure
Security is the product, not a feature of it. This page describes how we protect the Platform and how to report a vulnerability to us safely.
- Agreement
- Terms of Service
- Notice
- Privacy Policy
- Notice
- Cookie Notice
- Policy
- Acceptable Use Policy
01Our approach
SoniqPay handles payment credentials and transaction data on behalf of our customers. We design for least privilege, minimize the systems that touch cleartext card data, and treat every access to the vault as an auditable event.
02Platform security practices
- Encryption. Data encrypted in transit with TLS and at rest, with managed key rotation.
- Tokenization. Card data is tokenized on capture; cleartext primary account numbers exist only inside the vault boundary, for the duration of a Provider call.
- Access control. Role-based access, least-privilege administrative accounts, and mandatory multi-factor authentication for internal systems.
- Logging and monitoring. Every token access is logged with actor, purpose, and destination; infrastructure and application telemetry is centrally monitored.
- Secure development. Peer review, dependency scanning, and secrets scanning in the development pipeline.
- Testing. Third-party penetration testing of the Platform and its integrations.
- Resilience. Backups, recovery testing, and a documented incident response process.
Confirm each of these statements is accurate for the production environment before publishing. Do not publish a control that is not yet implemented.
03Compliance status
Card data is handled within a PCI-compliant vault environment provided through our platform partner, which for most integrations keeps merchant scope to SAQ A. Independent SOC 2 and PCI attestation are planned as the direct stack matures. We will state our position plainly rather than imply certifications we do not hold.
Current documentation available to customers under NDA can be requested at security@soniqpay.com.
04Reporting a vulnerability
If you believe you have found a security vulnerability in the Platform or on soniqpay.com, please report it to security@soniqpay.com. Include a description of the issue, the steps to reproduce it, the potential impact, and any supporting material.
Please report privately and give us reasonable time to remediate before any public disclosure. Do not open a public issue, post details on social media, or share them with third parties in the interim.
05Safe harbor
We will not pursue or support legal action against researchers who act in good faith and comply with this policy. If a third party brings action against you for research conducted in accordance with this policy, we will make it known that your activity was authorized.
Good faith means: making a genuine effort to avoid privacy violations, data destruction, and service disruption; accessing only the minimum data necessary to demonstrate an issue; and stopping and reporting immediately if you encounter customer or cardholder data.
06Scope
In scope
- soniqpay.com and its subdomains
- the SoniqPay dashboard
- the public API and sandbox environment
- official SoniqPay SDKs
Out of scope
- third-party services and Provider systems not operated by SoniqPay
- findings from automated scanners without a demonstrated, exploitable impact
- denial of service, volumetric, or resource exhaustion testing
- social engineering, phishing, or physical attacks against our staff or facilities
- missing security headers, cookie flags, or best-practice recommendations without a demonstrated impact
- vulnerabilities requiring a rooted or jailbroken device, or a compromised local environment
07What to expect
- acknowledgement of your report within 2 business days;
- an initial assessment and severity triage within 5 business days;
- regular updates while we work on a fix; and
- notification when the issue is resolved.
Decide whether a paid bug bounty will be offered. If not, say so explicitly here so researchers are not misled.
08Please do not
- access, modify, or delete data belonging to anyone other than yourself;
- perform testing against live merchant accounts or real cardholder data;
- degrade the availability or integrity of the Services; or
- demand payment as a condition of disclosing a vulnerability.
09Contact
Security reports: security@soniqpay.com. For general security questions from customers and prospects, contact your account team or security@soniqpay.com.