Security

Responsible Vulnerability Disclosure Policy

TroqPay's channel and rules for security research and responsible reporting of potential vulnerabilities.

Last updated: August 23, 2026
Troq Soluções Digitais LTDA · CNPJ 32.231.982/0001-19
Guidelines

Purpose and scope

How to research and report potential vulnerabilities in TroqPay assets.

1. Purpose

TroqPay values responsible collaboration with the security community. This Policy establishes a channel and rules for reporting potential vulnerabilities in technology assets controlled by TroqPay.

This Policy complements TroqPay's Information Security and Cybersecurity Policy. It does not authorize unauthorized access, service disruption, fraud, movement of funds, privacy violations, or any activity that violates the law or third-party rights.

Company: Troq Soluções Digitais LTDA, CNPJ 32.231.982/0001-19.

Version: 1.0.

Effective date: August 23, 2026.

Security contact: security@troqpay.com.

2. In-scope and out-of-scope assets

In scope are publicly accessible websites, applications, and APIs identified as TroqPay services and under TroqPay's operational control.

Customer, financial institution, partner, vendor, and other third-party systems, accounts, networks, applications, and data are out of scope, even when they integrate with or support services offered by TroqPay. Vulnerabilities in third-party assets should be reported to their respective owners.

If you are unsure whether an asset is owned by TroqPay or falls within scope, stop testing and contact TroqPay before proceeding.

Responsible research

Authorized conduct and limits

Conditions for good-faith, proportionate validation without impact on users or services.

3. Expected conduct

  • Test only as much as needed to confirm the potential vulnerability and assess its impact.
  • Use only accounts, credentials, data, and resources you own or are expressly authorized to use.
  • Stop testing immediately if you encounter personal or financial data, credentials, secrets, or nonpublic third-party information.
  • Do not copy, retain, alter, destroy, disclose, or exfiltrate data accessed during the research.
  • Preserve evidence securely and submit only what is necessary to reproduce the issue.
  • Keep the vulnerability confidential until TroqPay completes remediation or agrees to coordinated disclosure.
  • Comply with applicable law and third-party rights throughout the research.

4. Unauthorized activities

  • Denial of service, resource exhaustion, load testing, or any action that degrades availability.
  • Social engineering, phishing, vishing, smishing, spam, or physical attacks.
  • Brute force, credential stuffing, account takeover attempts, or use of credentials obtained from third parties.
  • Establishing persistence, installing malware, backdoors, ransomware, or modifying environments.
  • Moving funds or assets, or initiating real payments, withdrawals, transfers, conversions, or other financial transactions.
  • Accessing, altering, deleting, disclosing, or exfiltrating personal, financial, confidential, or third-party data.
  • Testing partner, vendor, customer, or other third-party systems without direct authorization from their owner.
  • Exploitation beyond what is strictly necessary for a safe proof of concept.
  • High-volume automated scanning or scanner-only reports without validation and reproducible impact.

5. Limited authorization for good-faith research

When research is conducted in good faith and in full compliance with this Policy, TroqPay will treat it, to the extent of the rights it controls, as authorized security research and does not intend to initiate legal action solely because of that activity.

This authorization does not cover damage, fraud, unauthorized access to or retention of data, movement of funds, violations of law, contract, or third-party rights, and it does not bind authorities, partners, vendors, or any other person. If in doubt, stop and request guidance before proceeding.

Reporting

How to report and what to expect

Information needed for analysis and coordinated disclosure rules.

6. How to report

Send your report to security@troqpay.com. Reports are accepted in Portuguese, English, or Spanish.

Avoid including personal data, credentials, keys, tokens, secrets, or third-party information. If such content is essential, first disclose its existence so TroqPay can provide an appropriate sharing method.

  • A clear description of the potential vulnerability and observed impact.
  • The affected asset, URL, endpoint, or functionality.
  • Minimal, reproducible validation steps.
  • Relevant technical evidence with sensitive information removed.
  • Approximate date and time of testing.
  • Contact details for follow-up, if you wish to receive a response.

7. Triage and remediation

TroqPay will seek to acknowledge receipt, assess validity, and prioritize the report based on risk, impact, and exploitability. TroqPay may request additional information during its analysis.

Investigation and remediation times vary according to complexity, severity, dependencies, and the measures required to preserve service security. Submitting a report does not guarantee a specific classification, immediate remediation, or public disclosure.

Duplicate, out-of-scope, or non-impactful reports, and reports generated exclusively by automated tools, may be closed or deprioritized.

8. Coordinated disclosure

Do not publicly disclose vulnerability details before TroqPay confirms remediation or expressly agrees on the timing and manner of disclosure.

TroqPay may limit information about its analysis or remediation when disclosure could increase risk, affect third parties, compromise an investigation, or violate legal or contractual duties.

Final provisions

Recognition, data, and effective date

Program limits, information handling, and Policy updates.

9. Recognition and rewards

TroqPay does not operate a public financial bug bounty program. Submitting a report does not create a right to payment, employment, benefits, or public recognition.

At its discretion and with the researcher's consent, TroqPay may recognize a relevant contribution after remediation. Such recognition is optional and does not create any present or future obligation.

10. Report data

Submitted information will be used to receive, validate, investigate, remediate, and document the report, protect rights, and meet applicable obligations. Personal data will be processed in accordance with TroqPay's Privacy Policy.

By submitting a report, the researcher represents that they have the right to share its contents and permits TroqPay to use them to analyze and remediate the potential vulnerability.

11. Review and effective date

TroqPay may update this Policy to reflect changes in its services, risks, processes, or applicable obligations. The version published at this address is the current version.

Version 1.0 takes effect on August 23, 2026 and remains valid until replaced.

Change log: Version 1.0, August 23, 2026, initial publication.