Sandbox previewNo real payments, payouts, or ownership transfers are active.

Responsible disclosure

Help keep the square safe.

Report vulnerabilities privately. Do not access other users' data, disrupt service, automate bids, social-engineer users, or test payment systems with real unauthorized instruments.

01

In scope

Authentication or authorization bypass, cross-site scripting, unsafe customization, SSRF through external links, malicious upload execution, payment or webhook replay, double sale, sensitive data exposure, and consequential admin abuse paths.

02

How to report

Use the Security category on the contact page until SECURITY_EMAIL is configured. Include a concise impact statement, affected URL, reproducible steps, and safe evidence. Never send passwords, payment credentials, PAN, Aadhaar, or OTPs.

03

Safe harbor intent

A final legal safe-harbor policy, response targets, reward status, disclosure coordination, and security contact will be published before launch. Good-faith reports receive a case reference and priority routing.

Still curious?

See the rules in motion.

Explore all 100 plots