Skip to content

Security: Xultech-LTD/devpayr

Security

SECURITY.md

Security Policy

DevPayr is a payment-agnostic licensing and enforcement platform.
While the core platform is private, this repository contains community contributions, examples, and documentation.
Security and privacy are extremely important to us.

This document explains how to report security issues responsibly.


πŸ” Supported Areas

You may report security vulnerabilities related to:

  • Example integrations (examples/)
  • SDK helper utilities (sdk/)
  • Public documentation errors that could mislead users into insecure implementations
  • Repository configuration or workflows that may expose risks

Note:
Reports about the private DevPayr platform are also welcomed, but please do not disclose them publicly.


🚫 NOT Supported Here

Please do not submit the following as security issues:

  • General feature requests
  • Billing or account issues
  • License key problems unrelated to security
  • Attempts to reverse-engineer or extract private DevPayr code
  • Vulnerabilities caused by user-side misconfiguration
  • Social engineering speculation

πŸ“¬ Reporting a Vulnerability

To report a security vulnerability:

1. Email us directly

Send your report to:

security@devpayr.com
(If unavailable, use support@devpayr.com)

Please include:

  • A clear description of the issue
  • Steps to reproduce
  • Impact assessment
  • Any supporting screenshots or proof of concept

2. Do NOT open a public Issue

Security reports must remain confidential until resolved.


⚑ Our Response Process

After you submit your report:

  1. A maintainer will acknowledge receipt within 72 hours
  2. The issue will be validated and investigated
  3. We will communicate:
    • Whether it is accepted
    • Any required follow-up details
  4. A fix or update will be prepared
  5. You may be credited publicly

Response times may vary depending on severity.


πŸ›‘ Responsible Disclosure

Please follow responsible disclosure practices:

  • Do not publish the vulnerability before a fix is ready
  • Do not attack production systems or user accounts
  • Do not access data belonging to others
  • Avoid using automated scanners against DevPayr without permission

We deeply appreciate researchers who follow these guidelines.


🀝 Thank You

We value the time and expertise of developers and researchers who help us keep DevPayr secure and reliable.

Thank you for protecting the community.

β€” XulTech LTD (Maintainers of DevPayr)

There aren’t any published security advisories