Skip to content
GlocalPeTM

Security & Responsible Disclosure Policy

Legal & Compliance

This Security & Responsible Disclosure Policy (“Policy”) describes the security practices and responsible vulnerability-reporting framework applicable to GlocalPe [FULL LEGAL ENTITY NAME] (“GlocalPe”, “we”, “us” or “our”).

Effective
[EFFECTIVE DATE]
Last updated
[LAST UPDATED DATE]

Introduction

Effective Date: [●]

Last Updated: [●]

GlocalPe operates technology-enabled infrastructure supporting cross-border payments, international collections, foreign-exchange-related Services, settlement, APIs and related financial workflows.

Because GlocalPe Services may involve sensitive financial, business and personal information, security is a fundamental part of our operations.

This Policy covers:

  • security expectations for users and customers;
  • security of GlocalPe Services;
  • reporting of suspected vulnerabilities;
  • responsible security research;
  • handling of security reports;
  • prohibited security testing activities;
  • security incident reporting.

1. SECURITY COMMITMENT

GlocalPe seeks to maintain appropriate technical, organisational and operational safeguards designed to protect:

  • customer information;
  • transaction information;
  • account credentials;
  • API credentials;
  • financial information;
  • business information;
  • payment instructions;
  • systems and infrastructure.

Security controls may include:

  • access controls;
  • authentication;
  • encryption;
  • monitoring;
  • logging;
  • vulnerability management;
  • incident response;
  • fraud prevention;
  • security testing;
  • third-party security controls.

No system connected to the internet can be guaranteed to be completely secure.

2. SECURITY GOVERNANCE

GlocalPe maintains security processes appropriate to the nature and scale of its Services.

These processes may include:

  • security policies;
  • access management;
  • least-privilege controls;
  • system monitoring;
  • vulnerability assessment;
  • security testing;
  • incident management;
  • backup and recovery;
  • third-party risk management;
  • employee security awareness.

3. ACCESS CONTROL

Access to GlocalPe systems and information is controlled based on business requirements.

Where appropriate, GlocalPe may apply:

  • role-based access;
  • least-privilege access;
  • authentication controls;
  • privileged-access controls;
  • access reviews;
  • logging and monitoring.

4. CUSTOMER ACCOUNT SECURITY

Customers are responsible for maintaining the security of their accounts.

Customers should:

  • use strong and unique passwords;
  • enable multi-factor authentication where available;
  • protect authentication credentials;
  • never share OTPs or authentication codes;
  • avoid using compromised devices;
  • keep browsers and operating systems updated;
  • log out from shared devices;
  • promptly report suspicious activity.

5. API SECURITY

Business customers using GlocalPe APIs are responsible for protecting:

  • API keys;
  • access tokens;
  • client credentials;
  • webhook secrets;
  • authentication credentials.

Customers must not:

  • publish API credentials in public repositories;
  • share credentials with unauthorised persons;
  • embed sensitive credentials in client-side applications where inappropriate;
  • intentionally bypass API security controls;
  • use credentials belonging to another customer.

Compromised credentials should be reported immediately.

6. TRANSACTION SECURITY

Customers should verify transaction details before confirming payment instructions.

This includes:

  • payer information;
  • beneficiary information;
  • account details;
  • amount;
  • currency;
  • transaction purpose.

Customers should promptly report suspected:

  • unauthorised transactions;
  • fraudulent transactions;
  • account takeover;
  • beneficiary manipulation;
  • suspicious API activity.

7. ENCRYPTION

GlocalPe may use encryption and related security technologies to protect information:

  • during transmission;
  • at rest;
  • within sensitive systems;

where appropriate to the relevant Service and risk.

The specific technical implementation may vary by system and infrastructure.

8. SECURITY MONITORING

GlocalPe may monitor systems and activity for:

  • unauthorised access;
  • fraud;
  • abuse;
  • malicious activity;
  • account compromise;
  • unusual behaviour;
  • security incidents.

Monitoring may include:

  • system logs;
  • authentication activity;
  • API activity;
  • transaction activity;
  • security alerts;
  • infrastructure events.

9. FRAUD PREVENTION

GlocalPe may use automated and manual controls to identify potentially fraudulent or suspicious activity.

Such controls may result in:

  • additional verification;
  • transaction holds;
  • transaction rejection;
  • account restrictions;
  • security investigations.

These measures are intended to protect customers and the integrity of the Services.

10. VULNERABILITY MANAGEMENT

GlocalPe may conduct or commission security activities including:

  • vulnerability assessments;
  • penetration testing;
  • code review;
  • dependency monitoring;
  • security configuration review;
  • infrastructure assessment;
  • remediation tracking.

The scope and frequency of such activities may vary according to risk.

11. RESPONSIBLE DISCLOSURE

GlocalPe welcomes good-faith reports of security vulnerabilities affecting its Services.

Security researchers, customers, developers and other individuals may report suspected vulnerabilities through the designated security channel.

Security Email: [security@glocalpe.com]

Where possible, reports should include sufficient information for GlocalPe to reproduce and investigate the issue.

12. WHAT SHOULD BE REPORTED

Examples of potentially reportable vulnerabilities include:

  • authentication bypass;
  • authorisation flaws;
  • privilege escalation;
  • sensitive information exposure;
  • API security vulnerabilities;
  • account takeover vulnerabilities;
  • payment-manipulation vulnerabilities;
  • injection vulnerabilities;
  • server-side vulnerabilities;
  • insecure direct object references;
  • significant security misconfigurations;
  • cryptographic weaknesses;
  • other vulnerabilities that could materially compromise GlocalPe Services.

13. REPORT CONTENT

A useful vulnerability report should include, where available:

  • vulnerability description;
  • affected URL, endpoint or component;
  • reproduction steps;
  • proof of concept;
  • expected behaviour;
  • actual behaviour;
  • security impact;
  • affected account or environment;
  • relevant screenshots or logs;
  • researcher's contact information.

Researchers should provide only the minimum information and evidence necessary to demonstrate the vulnerability.

14. DO NOT INCLUDE SENSITIVE DATA

Researchers must not intentionally include or retain unnecessary:

  • personal information;
  • payment information;
  • authentication credentials;
  • API keys;
  • financial information;
  • customer information.

If sensitive information is accidentally accessed, the researcher should:

  • stop testing the affected area;
  • avoid further accessing the information;
  • avoid copying or distributing it;
  • securely delete any unnecessary copies;
  • notify GlocalPe promptly.

15. GOOD-FAITH SECURITY RESEARCH

GlocalPe considers security research to be responsible where the researcher:

  • acts in good faith;
  • avoids unnecessary harm;
  • minimises data access;
  • does not disrupt Services;
  • does not access other users' information unnecessarily;
  • reports vulnerabilities promptly;
  • gives GlocalPe reasonable opportunity to investigate and remediate.

16. TESTING LIMITATIONS

Security research must be conducted in a manner that avoids disruption to GlocalPe Services.

Researchers must not intentionally:

  • disrupt availability;
  • degrade performance;
  • destroy or modify data;
  • interrupt payment processing;
  • interfere with financial settlement;
  • interfere with other customers;
  • bypass security controls beyond what is reasonably necessary to demonstrate the vulnerability.

17. PROHIBITED TESTING

The following activities are prohibited unless expressly authorised in writing by GlocalPe:

  • denial-of-service attacks;
  • distributed denial-of-service attacks;
  • stress testing against production systems;
  • destructive testing;
  • ransomware;
  • malware deployment;
  • phishing;
  • credential theft;
  • social engineering;
  • impersonation of employees or customers;
  • physical intrusion;
  • attacks against employees;
  • attacks against third-party infrastructure;
  • attacks against financial institutions;
  • attacks against Payment Partners;
  • attacks against other customers;
  • automated high-volume scanning that may materially affect Services.

18. NO SOCIAL ENGINEERING

Researchers must not attempt to obtain access by:

  • impersonating GlocalPe employees;
  • impersonating customers;
  • contacting employees under false pretences;
  • phishing;
  • requesting credentials;
  • manipulating support personnel.

19. NO TESTING OF OTHER CUSTOMERS

Researchers must not intentionally access, modify or test another customer's:

  • account;
  • transactions;
  • payment information;
  • personal information;
  • API credentials;
  • business information.

Where a vulnerability unexpectedly exposes another customer's information, testing must stop immediately.

20. NO FINANCIAL TRANSACTIONS FOR TESTING

Researchers must not conduct transactions for the purpose of generating:

  • financial gain;
  • fraudulent refunds;
  • unauthorised payouts;
  • settlement manipulation;
  • chargeback abuse;
  • fee avoidance.

If a vulnerability requires a transaction to demonstrate impact, the researcher should use the minimum-risk approach and contact GlocalPe where appropriate before proceeding.

21. THIRD-PARTY SYSTEMS

GlocalPe may depend on:

  • banks;
  • payment institutions;
  • payment networks;
  • FX providers;
  • KYC/KYB providers;
  • cloud providers;
  • technology providers;
  • other Payment Partners.

Researchers must not test third-party systems merely because they are connected to GlocalPe.

Reports concerning third-party infrastructure may be forwarded to the relevant provider where appropriate.

22. RESPONSIBLE TESTING OF PAYMENT FLOWS

Payment systems require additional caution.

Researchers must not attempt to:

  • redirect another person's funds;
  • manipulate settlement;
  • alter transaction amounts;
  • bypass transaction controls;
  • exploit currency conversion;
  • manipulate exchange rates;
  • interfere with beneficiary information;
  • generate unauthorised payouts.

Where a security issue affects payment integrity, researchers should report the issue without attempting to extract financial value from it.

23. PROOF OF CONCEPT

Proof-of-concept testing should be:

  • minimal;
  • controlled;
  • reversible;
  • non-destructive.

Researchers should demonstrate only the level of access necessary to establish the vulnerability.

24. AUTOMATED SCANNING

Automated tools may be used only where they do not materially affect GlocalPe systems.

Researchers should avoid:

  • excessive request rates;
  • uncontrolled crawling;
  • resource-intensive payloads;
  • large-scale enumeration;
  • activity that may trigger operational disruption.

GlocalPe may block or rate-limit automated activity that presents a security or availability risk.

25. VULNERABILITY REPORT ACKNOWLEDGEMENT

Where practicable, GlocalPe will acknowledge receipt of a vulnerability report.

Acknowledgement does not mean that:

  • the vulnerability has been validated;
  • the report qualifies for a reward;
  • GlocalPe accepts liability;
  • the reported behaviour constitutes a security vulnerability.

26. VULNERABILITY ASSESSMENT

GlocalPe may assess reported vulnerabilities based on factors including:

  • exploitability;
  • impact;
  • affected systems;
  • affected users;
  • confidentiality impact;
  • integrity impact;
  • availability impact;
  • likelihood of exploitation;
  • existing security controls.

GlocalPe may use an established vulnerability-severity methodology where appropriate.

27. DUPLICATE REPORTS

Where multiple researchers report the same vulnerability, GlocalPe may treat the first sufficiently detailed and reproducible report as the primary report for disclosure or recognition purposes.

28. REPORT CONFIDENTIALITY

GlocalPe will handle vulnerability reports appropriately and may restrict access to reports to personnel who require the information for investigation and remediation.

Researchers should also keep non-public vulnerability information confidential until coordinated disclosure is agreed.

29. COORDINATED DISCLOSURE

GlocalPe encourages coordinated disclosure.

Researchers should provide GlocalPe reasonable time to:

  • validate the issue;
  • assess impact;
  • develop remediation;
  • deploy corrective measures;
  • coordinate disclosure where appropriate.

Researchers should not publicly disclose a vulnerability before allowing reasonable time for GlocalPe to address it, particularly where disclosure could expose customers or financial systems to harm.

30. PUBLIC DISCLOSURE

If a researcher intends to publish a vulnerability, the researcher is encouraged to contact GlocalPe in advance.

Where appropriate, GlocalPe may coordinate:

  • disclosure timing;
  • technical details;
  • affected versions;
  • remediation information;
  • researcher attribution.

GlocalPe does not guarantee that it will agree to every proposed disclosure timeline.

31. SECURITY REPORT RESPONSE

Depending on the nature of the report, GlocalPe may:

  • request additional information;
  • reproduce the vulnerability;
  • classify its severity;
  • remediate the issue;
  • implement compensating controls;
  • monitor for exploitation;
  • coordinate with relevant Payment Partners;
  • close the report where no actionable vulnerability is identified.

32. REMEDIATION

GlocalPe may remediate vulnerabilities through:

  • code changes;
  • configuration changes;
  • access-control changes;
  • infrastructure changes;
  • security rules;
  • monitoring;
  • partner coordination;
  • other appropriate controls.

The time required will depend on severity, complexity and operational risk.

33. SECURITY INCIDENT REPORTING

Customers and third parties should promptly report suspected security incidents, including:

  • unauthorised account access;
  • compromised credentials;
  • leaked API keys;
  • suspected data exposure;
  • malware affecting GlocalPe integrations;
  • suspicious payment activity;
  • account takeover;
  • other security incidents.

Security Incident Email: [security@glocalpe.com]

Urgent matters should be clearly marked as URGENT SECURITY INCIDENT.

34. COMPROMISED API CREDENTIALS

If an API key or access credential is suspected to be compromised, the customer should immediately:

  • revoke or rotate the credential where possible;
  • stop unauthorised integrations;
  • review recent API activity;
  • contact GlocalPe;
  • provide relevant transaction or request references.

35. SECURITY COMMUNICATIONS

GlocalPe may contact customers concerning:

  • security incidents;
  • suspicious activity;
  • compromised credentials;
  • vulnerability remediation;
  • required security actions.

Customers should ensure that their registered contact information remains current.

36. RESPONSIBLE DISCLOSURE PROTECTION

Where legally permissible and subject to compliance with this Policy, GlocalPe does not intend to pursue legal action against researchers solely for good-faith security research that:

  • follows this Policy;
  • avoids unnecessary harm;
  • does not involve fraud or financial gain;
  • does not intentionally access unnecessary personal or financial information;
  • does not disrupt Services;
  • promptly reports discovered vulnerabilities.

This statement does not provide immunity from third-party claims, applicable laws or conduct outside the scope of responsible security research.

37. EXCLUSIONS

The following generally do not qualify as security vulnerabilities by themselves:

  • missing security headers with no demonstrated security impact;
  • informational findings;
  • best-practice recommendations without exploitable impact;
  • self-XSS without meaningful security impact;
  • rate-limit observations without demonstrated risk;
  • issues affecting unsupported or obsolete software;
  • publicly known third-party vulnerabilities that do not affect GlocalPe;
  • theoretical vulnerabilities without practical impact.

GlocalPe may assess each report based on its actual circumstances.

38. SECURITY RESEARCH REWARDS

Unless expressly stated otherwise, GlocalPe does not guarantee:

  • monetary rewards;
  • recognition;
  • bounty payments;
  • compensation

for vulnerability reports.

If GlocalPe operates a formal bug-bounty or security-research programme, that programme's specific terms will govern eligibility and rewards.

39. NO GUARANTEE OF RESPONSE TIME

GlocalPe will make reasonable efforts to review security reports.

Response and remediation times may vary based on:

  • severity;
  • complexity;
  • availability of information;
  • affected infrastructure;
  • third-party dependencies;
  • operational requirements.

40. PRIVACY

Security reports may contain personal or technical information.

Such information will be handled in accordance with the GlocalPe Privacy Policy and applicable data-protection requirements.

41. THIRD-PARTY DISCLOSURE

Where a reported vulnerability relates to a Payment Partner or other third-party provider, GlocalPe may share relevant information with that provider where necessary to investigate or remediate the issue.

42. POLICY CHANGES

GlocalPe may update this Policy from time to time to reflect:

  • changes in Services;
  • security practices;
  • technology;
  • regulatory requirements;
  • responsible-disclosure practices;
  • changes in infrastructure.

The latest version will be published through the appropriate GlocalPe channel.

43. CONTACT

Security & Responsible Disclosure

Security Email: [security@glocalpe.com]

Security Contact: [●]

Security Incident Reporting: [●]

Vulnerability Disclosure: [●]

General Support: [●]

Grievance Officer: [●]

Registered Office: [●]

Website: [●]

Policy Version: [●]

Effective Date: [●]

Last Updated: [●]

Questions about this document?

Write to support@glocalpe.com or use the contact form.

Back to Legal Center