Report vulnerabilities to security@syzm.ai.
Include reproduction steps, impact, and affected component.
- Webhook signature verification and replay protection
- API key storage/rotation
- Queue tampering or privilege escalation paths
- Data leakage from logs or exports
- Never ingest raw PAN, CVV, or full card track data.
- Store only tokenized/payment-processor references and non-PCI metadata.
- Redact IDs in logs when possible.
- Acknowledge report: within 2 business days
- Triage classification: within 5 business days
- High/Critical patch target: within 14 calendar days