1.Current Public Information
Review the Security page, Security Policy, Privacy Policy, and Compliance Information for SEZA's current public statements. These pages are not independent certifications or audit reports.
2.Responsible Disclosure
Security research must avoid disrupting live services, changing or deleting data, accessing data beyond what is necessary to demonstrate a finding, social engineering, denial-of-service testing, and public disclosure before SEZA has had a reasonable opportunity to investigate.
3.Report a Vulnerability
Email security@sezapos.com with the affected page or feature, reproduction steps, potential impact, and a safe way to contact you. Please do not include unnecessary personal information or full payment credentials.
4.Response Expectations
SEZA will review good-faith reports and prioritize them based on reproducibility, severity, affected data, and risk to merchants. A submission does not create a contractual right to payment, public credit, or a specific remediation deadline unless SEZA agrees in writing.
