Security
Report a security vulnerability.
We welcome good-faith research that helps protect BoomPay customers, repair businesses, partners, and systems.
Email security@boompay.caReport securely
Secure communication
BoomPay takes security seriously and strictly follows the applicable OpenPGP standards and RFCs for GPG-compatible secure communication.
Encrypt your report
We strongly encourage security researchers to encrypt vulnerability reports with our public key and send them to security@boompay.ca.
Download the BoomPay public keyTo maintain operational security, we strongly recommend sending GPG signed and encrypted emails. You can easily do this using privacy-focused email providers that natively support GPG, like ProtonMail, or by using security-conscious local email clients and browser extensions such as Thunderbird or Mailvelope.
VDP
Vulnerability disclosure policy
This policy explains which systems and research activities are covered, how to report a potential vulnerability, and what you can expect from BoomPay.
Safe harbor
If you make a good-faith effort to comply with this policy during your security research, BoomPay considers that research authorized. We will work with you to understand and resolve the issue, and we will not initiate or support legal action related to compliant research. If a third party initiates legal action against you for activities conducted in accordance with this policy, we will make it known that your research was authorized under our VDP guidelines.
To the limited extent that BoomPay's terms would prevent research authorized by this policy, we waive those restrictions for compliant research. This safe harbor applies only to legal claims under BoomPay's control and does not bind independent third parties, prosecutors, regulators, or courts. You must still comply with applicable law. If you are unsure whether planned research is covered, email us before you continue.
Scope
The root domain boompay.ca and BoomPay-owned or operated services under *.boompay.ca are in scope.
Out of scope
- Third-party vendors, services, applications, or infrastructure that BoomPay does not own or operate, even when linked from a BoomPay service.
- Social engineering against BoomPay staff, contractors, customers, partners, or service providers, including phishing, vishing, impersonation, and pretexting.
- Physical attacks, office-access testing, tailgating, device theft, or attempts to access facilities.
Report vulnerabilities in an out-of-scope vendor system to that vendor. If ownership or scope is unclear, ask us before testing.
Rules of engagement
To remain within this policy, you must:
- Make every effort to avoid privacy violations, service disruption, degraded system performance, and the destruction or manipulation of data.
- Do not perform denial-of-service or distributed denial-of-service testing, send excessive traffic, or interfere with production availability.
- Do not use credential stuffing, password spraying, malware, destructive payloads, or high-volume automated scanning.
- Use an exploit only as far as needed to confirm that a vulnerability exists. Do not establish persistence, pivot to other systems, exfiltrate data, or access more records than the minimum proof requires.
- Use only accounts and data that you own or have explicit permission to use.
- Do not create or change real payments, loans, signatures, notices, liens, recovery actions, customer messages, or other business transactions.
- Stop testing and report immediately if you encounter personal, financial, authentication, or other sensitive data. Do not copy, retain, alter, or disclose it.
- Report the vulnerability promptly and give BoomPay a reasonable opportunity to investigate and remediate it before public disclosure.
- Do not threaten, extort, or demand payment in exchange for withholding a report or disclosure.
What to include
Send the affected host or URL, a clear description of the issue and its potential impact, reproducible steps, and a minimal proof of concept. Include screenshots or logs only when they do not expose unnecessary personal or confidential information.
We will acknowledge and assess actionable reports, work to validate the issue, and share progress when practical. Information submitted through this program will be used for defensive purposes, including investigation and remediation.
Bounties and rewards
BoomPay currently operates a VDP-only program focused on secure disclosure. We do not offer cash bounties at this time. Valid and actionable reports will be rewarded with company swag and, with the researcher's permission, public recognition in our Hall of Fame.
Hall of Fame
We thank researchers who help us improve BoomPay's security. Recognition is published only with the researcher's permission.
No researchers are listed yet.
Found something?
Encrypt the details and send them through our official security channel.