Skip to content

Security: FITdeike/noxpospay

Security

SECURITY.md

Security policy

NoxPos takes merchant and payment integrity seriously. This repository is a public documentation / project page only — it does not contain production application source.

Reporting a vulnerability

Please report security issues privately:

Include:

  1. What you found and potential impact
  2. Steps to reproduce (or a clear description)
  3. Affected URL / surface if known (website, cashier, hosted pay, plugin)
  4. Whether you plan to disclose publicly and on what timeline

We will acknowledge reports as soon as practical and work with you on a fix timeline for confirmed issues.

Out of scope for this repository

Do not open public GitHub issues that include:

  • Live API keys, tokens, or session cookies
  • Private keys / seed phrases
  • Exploit payloads against production systems
  • Personal data of merchants or customers

Safe harbor (good-faith research)

Good-faith security research that:

  • avoids destructive testing
  • does not access other users’ data
  • reports privately first

…is welcome. We ask that you give us a reasonable window to remediate before public disclosure.

Merchant hygiene (quick tips)

  • Never share Integration API keys in screenshots, tickets, or public repos
  • Keep receiving wallets under your own control
  • Rotate keys if you suspect exposure
  • Prefer official downloads and docs from noxpospay.com

There aren't any published security advisories