Responsible disclosure
EventPay builds payment and event technology used by organisers and their attendees. Protecting that data is core to what we do, and we value the security research community’s help in keeping our platform safe. If you believe you have found a security vulnerability in one of our systems, we want to hear about it — and we commit to working with you in good faith to verify and fix it.
Scope
In scope
- The EventPay platform and its web applications under *.eventpay.be (the organiser back-office, the EventApp wallet pages at <organiser>.eventpay.be)
- The public EventPay API (see docs.eventpay.be)
- The production infrastructure EventPay operators for the platform
Out of scope
- EventPay’s public marketing/corporate website (eventpay.be homepage and marketing pages)
- Third-party services we rely on but don’t operator – Payment Providers (MulitSafepay, Mollie, Paynovate), acquirers, CCV terminals, hosting / CDN, email, forms.eventpay.be (tally.so). Report those to the relevant provider.
- Data, content or configuration owned by our customers/organisers
- Findings that require physical access, social engineering or our staff, customers or partners
If you are unsure whether something is in scope, ask us first via the report form.
Rules of engagement
Please do
- Act in good faith and avoid privacy violations, data destruction, and any interruption or degradation of our services.
- Only interact with accounts you own or have explicit permission to test, using your own test data.
- Access only the minimum data necessary to demonstrate the issue — do not download, copy, retain, alter or delete data that isn’t yours.
- Stop as soon as you have confirmed the vulnerability, and report it — do not pivot, escalate or dig further.
- Keep the vulnerability confidential until we have resolved it and agreed disclosure with you.
- Securely delete any confidential data you obtained during your research as soon as the vulnerability has been resolved.
Prohibited – this voids safe harbor and may be unlawful
- Denial-of-service (DoS/DDoS), spam, brute-force or resource-exhaustion testing.
- Social engineering or phishing of EventPay, its staff, customers or partners; physical attacks against facilities.
- Deploying malware, backdoors or any form of persistence.
- Deleting, modifying or exfiltrating data; degrading or interrupting our services.
- Testing third-party systems, or accessing data belonging to other users.
How to report
Preferred: submit the report form – it captures everything we need (affected asset, vulnerability type, severity, reproduction steps, impact, and optional supporting files).
Or email: info <at> eventpay.be
Please include the affected asset/URL, a clear description, step-by-step reproduction or proof of concept, and the potential impact. Screenshots or a short PoC help us triage faster. You may report anonymously; leaving contact details lets us coordinate a fix and credit you.
Safe harbour (Belgian legal framework)
Belgium has a legal framework for coordinated vulnerability disclosure, in force since February 2023 and overseen by the Centre for Cybersecurity Belgium (CCB). EventPay considers security research carried out in accordance with this policy to be authorised, and we will not pursue or support legal action against researchers who:
- act in good faith, without fraudulent intent or intent to cause harm;
- stay within this policy’s scope and rules of engagement;
- limit their actions to what is strictly necessary to find and demonstrate a vulnerability; and
- report the vulnerability to us promptly and keep it confidential until coordinated disclosure.
What you can expect from us
- We aim to acknowledge your report within 10 business days.
- We will validate the issue, keep you informed of our progress (where you have provided contact details), and let you know when it is fixed.
- We will coordinate the timing of any public disclosure with you.
- With your consent, we are happy to credit you for the discovery; if you prefer to remain anonymous, we will respect that.
- We treat your report and your personal details confidentially, and will not share them with third parties without your consent unless we are legally required to do so.
- We do not currently run a paid bug-bounty program — reports are handled on a good-faith, coordinated-disclosure basis.
Hall of Fame
—