NoxPos takes merchant and payment integrity seriously. This repository is a public documentation / project page only — it does not contain production application source.
Please report security issues privately:
- Email: cashier@noxpospay.com
- Subject line suggestion:
[Security] short summary
Include:
- What you found and potential impact
- Steps to reproduce (or a clear description)
- Affected URL / surface if known (website, cashier, hosted pay, plugin)
- Whether you plan to disclose publicly and on what timeline
We will acknowledge reports as soon as practical and work with you on a fix timeline for confirmed issues.
Do not open public GitHub issues that include:
- Live API keys, tokens, or session cookies
- Private keys / seed phrases
- Exploit payloads against production systems
- Personal data of merchants or customers
Good-faith security research that:
- avoids destructive testing
- does not access other users’ data
- reports privately first
…is welcome. We ask that you give us a reasonable window to remediate before public disclosure.
- Never share Integration API keys in screenshots, tickets, or public repos
- Keep receiving wallets under your own control
- Rotate keys if you suspect exposure
- Prefer official downloads and docs from noxpospay.com