VisaOSTrust CentreHomepage
Appearance
Start your application
TRUST

Report a security issue

If you have found a weakness in VisaOS, please tell us before you tell anyone else. We will not pursue legal action against anyone who reports a genuine issue in good faith.

VERSION 1.0LAST UPDATED 29 AUGUST 2026

Write to

help@visa-os.com

Please use the subject line Security. There is no separate security address and no PGP key — this is the route, and a report sent here reaches us.

What to report

  • Anything that could expose another person’s application, documents or account.
  • Authentication or session weaknesses — sign-in bypass, token reuse, privilege escalation.
  • Injection, file-upload handling flaws, or server-side request forgery.
  • Exposed credentials, keys or configuration.
  • Payment or export flows that can be manipulated.
  • Anything that makes you think “that surely isn’t meant to work like that”.

What to include

  • What you found, and clear steps to reproduce it.
  • The URL, browser and approximate time.
  • What an attacker could realistically achieve with it.
  • Whether you accessed, altered or retained any data that was not yours.
  • How you would like to be credited, if the issue is confirmed.

Testing that is not permitted

  • Accessing, downloading, altering or retaining another person’s application or documents.
  • Denial-of-service, load testing, or high-volume automated scanning.
  • Social engineering of our team, our users or our suppliers.
  • Physical attempts against any premises or hardware.
  • Testing against third-party services such as Stripe, PayPal or Anthropic.

Privacy expectations

If you encounter personal information while investigating, stop, do not retain a copy, and tell us what you saw. Do not use, share or publish anyone’s data. We will treat your report confidentially and will not share your identity outside the people who need it to fix the issue, unless you ask us to or the law requires it.

Good-faith reporting

If you act in good faith, avoid privacy violations and destruction of data, and give us a reasonable chance to fix the problem before disclosing it, we will treat your research as authorised and will not take or support legal action against you.

What happens next

We will acknowledge your report, investigate, and tell you what we found and when it is fixed. We do not publish acknowledgement or resolution targets, because we would rather publish times we can honour than reassuring numbers.

VisaOS does not operate a bug-bounty programme and does not offer payment for reports. If that changes it will be stated here explicitly. We are grateful either way, and will credit you if you would like us to.

↑ Back to top