Skip to main content

Responsible Security Disclosure

Version 1.0 · Last updated:

If you believe you have found a security vulnerability in Rainbow Pay's website or publicly exposed services, please report it privately to security@rainbowpay.hk. We welcome good-faith reports, will work with you to understand and fix the issue, and ask that you give us reasonable time to do so before disclosing it. We do not run a bug bounty programme at present.

1. How to report

Please send your report to security@rainbowpay.hk. Do not report vulnerabilities through public channels, social media, the general contact forms or our support channels.

Our contact details for security reports are also published in machine-readable form at /.well-known/security.txt.

To help us assess your report, please include:

  • the affected URL, host, endpoint or component;
  • a description of the vulnerability and its potential impact;
  • step-by-step instructions to reproduce it, including any proof-of-concept code, requests and responses, or screenshots;
  • the date and time of your testing, and the IP address(es) you tested from; and
  • how we can contact you, and whether you would like to be credited.
If your testing exposed personal data, payment data or credentials, do not include that data in your report. Describe what was accessible instead.

2. Scope

This policy covers the rainbowpay.hk website and publicly exposed Rainbow Pay services, such as our developer documentation and publicly reachable interfaces.

The following are out of scope:

  • systems and services operated by third parties, including our payment partners, payment schemes, hosting and service providers — please report issues in those systems to the relevant provider;
  • findings that rely on physical access, social engineering or compromised user devices;
  • reports produced only by automated scanners without a demonstrated, exploitable impact; and
  • denial-of-service vulnerabilities that can only be demonstrated by degrading the service.

3. Testing in good faith

When investigating and reporting a vulnerability, you must:

  • not access, modify, delete or retain data belonging to merchants, their customers or any other person beyond the minimum necessary to demonstrate the vulnerability, and securely delete any such data once your report is submitted;
  • not perform destructive testing, or take any action that could alter, damage or degrade our systems or data;
  • not use social engineering, phishing or any other deception against our staff, merchants or partners;
  • not attempt physical access to our offices, facilities or equipment;
  • not carry out denial-of-service or distributed denial-of-service attacks;
  • not use automated or high-volume scanning that degrades the performance or availability of our services;
  • use only accounts and credentials that you own or are explicitly authorised to use;
  • comply with applicable law; and
  • keep details of the vulnerability confidential, and not disclose it publicly or to any third party until we have remediated it or agreed a disclosure date with you.

Please allow us a reasonable period to investigate and remediate before any disclosure. Complex issues, or issues involving third parties, may take longer to resolve, and we will keep you informed.

4. What you can expect from us

If you report a vulnerability in accordance with this policy, we will:

  • acknowledge receipt of your report;
  • investigate it and let you know whether we have been able to confirm it;
  • keep you reasonably informed of our progress towards remediation;
  • agree with you, where appropriate, the timing and content of any public disclosure; and
  • credit you publicly for the finding once it is resolved, if you wish and where appropriate.

Where we are satisfied that research was conducted in good faith and in accordance with this policy, we intend not to pursue legal action against the researcher in respect of that research and we intend not to refer it to law enforcement. This does not apply to activity that breaches this policy or applicable law, and it cannot bind third parties.

5. Rewards

Rainbow Pay does not operate a bug bounty programme at present, and submitting a report does not create any entitlement to payment or other reward. Please do not make disclosure conditional on payment.

6. Changes to this policy

We may update this policy from time to time. The version number and effective date are shown at the top of this page.

Legal and regulatory information

Cookie preferences

Choose which optional cookies we may use. Strictly necessary cookies are always active because the website cannot work without them.

  • Strictly necessary

    Security, load balancing, form protection and remembering your cookie choice.

    Always active

Read the Cookie Policy