opago
Payment Compliance
About
About
Blog
FAQ
EN
EN
DE
Login
Login
Contact
EN English
DE German
Legal
Responsible Vulnerability Disclosure

Responsible Vulnerability Disclosure

We take security seriously — and so do you. Thank you for that. The security of our systems and the privacy of our users matter deeply to us. If you've discovered a vulnerability in one of our products, you're making a real contribution to a safer internet — and we genuinely appreciate that. This page explains how to share your findings with us safely and responsibly.

Our commitment to researchers

Security research is valuable work, and we want to make it easy for you to report findings without hesitation. If you act in good faith and follow the guidelines on this page, you have our commitment that we will not pursue legal action against you — and we will not involve law enforcement. Should a third party take legal action against you for activities that fall within this policy, we will make clear that your actions were conducted with our knowledge and authorization.

We ask only that you stay within the defined scope, avoid accessing data beyond what's necessary to demonstrate the issue, and give us a fair chance to fix it before disclosing publicly.

In short: act responsibly, and we've got your back — regardless of where in the world you're based.

Scope

In scope: Any opago-managed services, APIs, and web applications. Includes *.opago.com and *.opago-pay.com.

Out of scope: Third-party integrations, Denial of Service (DoS) attacks, social engineering & physical testing, or automated scanner results without manual verification.

How to report a vulnerability

Send us an email. To help us triage your report quickly, please include the following information:

  • A clear description of the issue — which URL, endpoint, or component is affected, what you found, and why it poses a security risk.
  • Step-by-step reproduction steps — the more detail the better. Screenshots, HTTP request/response logs, or proof-of-concept code are very welcome.
  • Potential impact — your assessment of what an attacker could do with this vulnerability.
  • Your environment — browser, OS, or tool version where relevant.
  • Your contact details & preferred alias — so we can keep you updated, and know how to credit you (if you'd like that).

Please do not exploit the vulnerability or access data beyond what's necessary to demonstrate it. And please keep your findings confidential until we've had a chance to remediate — we work under a 90-day coordinated disclosure window.

Create Vulnerability Report

What you can expect from us

  • Quick acknowledgement: We'll confirm receipt of your report within 3 business days.
  • Regular updates: We'll keep you in the loop as we investigate and resolve the issue.
  • Recognition: With your permission, we'll add you to our Hall of Thanks. Prefer to stay anonymous? No problem — no questions asked.

Wall of Thanks

Name / Alias URL Vulnerability

No entries yet. Be the first to responsibly disclose a vulnerability.

opago
Designed in Bavaria
opago is a digital asset payment and compliance service provider for financial institutions and enterprise customers
Services
Payment
Compliance
FAQ
Company
About
Blog
Contact
Social
LinkedIn
Twitter
Instagram
©2026 opago GmbH. All rights reserved.
Imprint Privacy Terms Complaint Form Security