This policy applies to the PlaceToPay Checkout Java SDK.
| Version | Supported |
|---|---|
| 1.x | Yes |
| < 1.0 | No |
Security fixes are provided for the latest stable major line.
Do not open a public issue for security reports.
- Email: security@placetopay.com
- Include: affected version, reproduction steps, impact assessment, and suggested fix if available.
- Acknowledgement target: 2 business days.
- Triage target: 7 business days.
- Coordinated fix/disclosure target: 30 days for high severity.
- Authentication/signing weaknesses.
- Sensitive data leakage in logs or errors.
- Webhook verification bypasses.
- Insecure defaults or dependency vulnerabilities.