Security & Coordinated Disclosure

Last updated 19th September, 2026

If you believe you have found a security vulnerability in a Halocard system, we want to hear about it. Email security@halocard.co and we will work the report with you.

This page is the policy referenced by our security.txt file. It sets out what we consider in scope, what we ask of you while you are testing, the protection you have from us if you follow it, and how quickly we will come back to you.

How to report

Send your report to security@halocard.co. We do not publish a PGP key today, so if a finding contains credentials or personal data, tell us that it does and we will arrange an encrypted channel before you send the detail.

Please do not open a public issue, post the finding on social media, or disclose it to a third party before we have had a chance to fix it.

  • A description of the issue and why you believe it is a security problem.
  • The exact URL, endpoint or host affected.
  • Step-by-step reproduction instructions, and a proof of concept if you have one.
  • Any accounts, IP addresses or timestamps you used, so we can find your traffic in our logs.
  • How you would like to be credited, if you want to be.

A report that lets us reproduce the issue is worth far more to us than a scanner export, and it is the difference between a fix this week and a fix next quarter.

What is in scope

The systems Halocard operates:

  • halocard.co — the marketing site.
  • secure.halocard.co — the Halocard application.
  • support.halocard.co — the help centre.
  • p.halocard.co — our analytics proxy.
  • The Halocard mobile applications, where published.

Anything else is out of scope by default. In particular, our card issuing and banking partners run their own infrastructure and their own disclosure programmes — please report issues in their systems to them directly, not to us.

What is out of scope

We will read every report, but the following are unlikely to be treated as vulnerabilities on their own:

  • Findings from automated scanners with no demonstrated impact.
  • Missing or misconfigured security headers, cookie flags or TLS ciphers with no working exploit.
  • Denial of service, volumetric testing, brute forcing, or anything that degrades service for other people.
  • Social engineering, phishing or physical attacks against Halocard staff, users or offices.
  • Self-XSS, clickjacking on pages with no sensitive action, and issues that require a fully compromised device or browser.
  • Email configuration findings (SPF, DKIM, DMARC) without a demonstrated spoofing path.
  • Vulnerabilities in third-party services we merely consume, which should go to that vendor.

What we ask of you

While you are testing, stay inside the boundaries below. They exist to protect our customers, not to make your work harder:

  • Only test against accounts and data that belong to you. Never access, modify or retain another person's account, card or transaction data.
  • If you do encounter personal data, stop, tell us what you saw, and delete your copy.
  • Do not run attacks that degrade or interrupt the service for others.
  • Do not attempt to move funds, issue cards, or transact against real merchants as part of a proof of concept.
  • Give us a reasonable window to fix the issue before disclosing it publicly. Ninety days from our acknowledgement is our default, and we are happy to agree something shorter or longer with you.

Safe harbour

If you make a good faith effort to follow this policy while researching and reporting a vulnerability, we will treat your research as authorised. Specifically:

  • We will not bring or support legal action against you, including under computer misuse or anti-circumvention laws, for activity that is within this policy.
  • We will not ask your internet provider or employer to act against you for that activity.
  • If a third party brings action against you for research that was within this policy, we will make it known that your activity was authorised.

This protection is ours to give and covers Halocard systems only. It cannot bind our partners or any other third party. If you are ever unsure whether a piece of testing is within scope, ask us first — we would far rather answer the question than have you guess.

Acting in good faith means you follow this policy. Deliberately accessing other people's data, extorting us, or trading a finding to someone else falls outside it.

What you can expect from us

  • We will acknowledge your report within 3 business days.
  • We will tell you whether we have reproduced and accepted the issue within 10 business days, along with our assessment of its severity.
  • We will update you at least every 14 days while the issue is open.
  • We will tell you when the fix is live, and confirm it with you before we close the report.
  • If you would like credit, we will name you once the fix has shipped. If you would rather stay anonymous, we will keep you out of it.

Halocard does not currently run a paid bug bounty, so we cannot promise a monetary reward. We can promise that your report will be read by an engineer, answered by a person, and acted on.

This policy

This page is the target of the Policy field in our security.txt file, published at halocard.co/.well-known/security.txt. That file is the authoritative contact record; if it and this page ever disagree, the file wins.

How we handle personal data day to day is a separate document — see our Privacy Policy.