Vulnerability Disclosure
How to report security vulnerabilities in the Pay Box Timers platform, and what to expect from us in return.
Introduction
Pay Box Timers is committed to keeping our platform, our customers, and our hardware secure. We welcome reports from security researchers who discover vulnerabilities in our systems, and we're committed to working with the community to verify, reproduce, and respond to legitimate reports. This policy describes how to report a vulnerability to us, what you can expect from us in return, and the ground rules for good-faith security research against our platform.
Scope
The following are in scope for security research and reporting:
- payboxtimers.com and its subdomains
- The customer, owner, and admin dashboards
- Public and authenticated API endpoints served by the platform
The following are out of scope:
- Third-party services we rely on but do not operate, including Stripe, our hosting provider, and email delivery providers — report those directly to the vendor
- Physical tampering with or theft of deployed hardware (timers, ESP32 controllers) in the field
- Social engineering of our staff, customers, or support channels
- Denial-of-service or load-testing attacks against our infrastructure
Reporting a Vulnerability
If you believe you've found a security vulnerability, please email info@limitedresources.us with the subject line starting [Security]. To help us triage and reproduce your report quickly, please include:
- A clear description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- The affected URL, endpoint, or component
- Any proof-of-concept code, screenshots, or request/response captures
Please report privately and give us a reasonable opportunity to investigate and remediate before disclosing the issue publicly or to any third party.
Safe Harbor
We will not pursue legal action against, or refer to law enforcement, any security researcher who makes a good-faith effort to comply with this policy. Good faith means: staying within the scope defined above, avoiding privacy violations, avoiding destruction or corruption of data, avoiding degradation or interruption of our services, and reporting any vulnerability found promptly and privately. If a third party initiates legal action against a researcher for activity conducted in accordance with this policy, we will make it known that the research was authorized.
Our Commitment
When you report a vulnerability in good faith, we commit to:
- Acknowledge receipt of your report within 3 business days
- Confirm the issue and keep you informed as we work toward a fix
- Handle your report and any personal information confidentially
- Publicly credit you for the discovery, if you would like, once the issue is resolved
This is a responsible disclosure program, not a paid bug bounty — we do not currently offer cash or credit rewards for reports.
Prohibited Testing
While researching, please do not:
- Run automated scanning tools that generate significant traffic or degrade service availability for other users
- Access, modify, or delete data belonging to other users or merchants
- Physically interfere with hardware (timers, ESP32 controllers) deployed at customer sites
- Attempt to pivot from a discovered vulnerability into a broader compromise of our infrastructure
Changes to This Policy
We may update this policy from time to time as our systems and processes evolve. Continued reporting of vulnerabilities to us after a published update constitutes acceptance of the updated policy.
Contact
Report vulnerabilities to info@limitedresources.us.
