Security disclosure policy
The machine-readable version of this page is at /.well-known/security.txt.
Found something? Email security@paybills.uz with enough detail to reproduce it. If you get no reply within five working days, resend to support@paybills.uz with "security" in the subject so it is not missed.
What we ask
- Give us a reasonable chance to fix the issue before you publish it.
- Use only accounts you created yourself. Do not access, change or keep anyone else's data, and stop as soon as you have enough to demonstrate the problem.
- No denial of service, no load or stress testing, no spam or social engineering of our staff, our customers or our partners.
- Do not attempt real payments to prove a payment bug. Tell us what you found and we will reproduce it ourselves.
What we commit to
- We acknowledge every report we receive, and we tell you what we decided rather than going quiet.
- We will not pursue legal action over research that follows this policy and is carried out in good faith.
- If you would like the credit, we will name you below once the issue is fixed. If you would rather not be named, say so and we will not.
In scope
paybills.uzand its subdomains, includingapi.paybills.uz- The PayBills Android app and the Telegram Mini App
Out of scope
- Findings on systems we do not operate: Cloudflare, Google Play, Telegram, our acquiring bank and Paynet. Report those to their owners.
- Reports produced only by an automated scanner, with no demonstrated impact.
- Missing hardening headers, weak TLS ciphers or similar, absent a concrete exploit.
- Anything that requires access to a victim's unlocked device or email account.
No bounty
We do not run a paid bug bounty and we do not want to imply one. What we offer is a fast, honest reply, a fix, and credit if you want it.
Acknowledgments
Nobody yet. This section lists researchers who have reported a confirmed issue to us and asked to be named.