Report a vulnerability
Email security@swipe.co.za. Include the affected hostname or product area, the time observed, the smallest safe reproduction, likely impact and a way to contact you.
Safe testing expectations
- Use accounts and data you own or are explicitly authorized to test.
- Do not disrupt a store, change balances, complete unauthorized transactions, access unrelated records or weaken availability.
- Do not use social engineering, physical intrusion, denial of service, destructive payloads or credential attacks.
- Stop when you have enough evidence to explain the issue.
What happens next
We will acknowledge the report, triage the potential impact, preserve relevant evidence, contain the risk where necessary and communicate through a named case. Resolution timing depends on severity, reproducibility and affected dependencies.
How SWIPE approaches security
Our product architecture uses scoped identity and authorization, separation between public and authenticated surfaces, protected secrets, encrypted transport, audit events, service health checks, controlled register assignments, backups and incident procedures. Controls evolve with the product and do not constitute a guarantee that every risk can be eliminated.
Urgent operational incidents
If a Till, manager phone, wallet or user account may be stolen or actively compromised, contact support and security immediately. Include the tenant, company, store, device or Till name and the last known legitimate activity. Do not continue using the suspected credential.
