Skip to content

Security: placetopay-org/sdk-checkout-java

Security

SECURITY.md

Security Policy

This policy applies to the PlaceToPay Checkout Java SDK.

Supported versions

Version Supported
1.x Yes
< 1.0 No

Security fixes are provided for the latest stable major line.

Reporting a vulnerability

Do not open a public issue for security reports.

  • Email: security@placetopay.com
  • Include: affected version, reproduction steps, impact assessment, and suggested fix if available.

Disclosure process

  • Acknowledgement target: 2 business days.
  • Triage target: 7 business days.
  • Coordinated fix/disclosure target: 30 days for high severity.

Scope highlights

  • Authentication/signing weaknesses.
  • Sensitive data leakage in logs or errors.
  • Webhook verification bypasses.
  • Insecure defaults or dependency vulnerabilities.

There aren't any published security advisories