1. Purpose
At ValueWay LLC, we take security seriously. This Security Policy defines how security researchers, partners, and customers can responsibly report potential vulnerabilities affecting our systems, websites, or APIs. Our goal is to maintain a secure environment for all users and continuously strengthen our platform’s resilience.
2. Scope
This Security Policy applies to all systems, websites, APIs, hosting environments, and
customer dashboards that are owned and operated by ValueWay LLC (including all
*.valuewayllc.com domains and subdomains).
Payment processing for credit and debit cards is handled by our approved third-party PCI DSS compliant payment processor. We do not store, process, or transmit cardholder data on our own systems. While these third-party processors are responsible for securing cardholder data within their environment, ValueWay LLC remains responsible for maintaining the security of our website, integrations, and the way we connect to those processors.
3. Reporting a Vulnerability
If you believe you have discovered a security or privacy issue, please report it responsibly to our team.
- Email: [email protected]
- PGP Encryption Key: View Key
When submitting a report, please include:
- A clear description of the vulnerability
- Steps to reproduce it
- Affected URLs or systems
- Relevant technical details or logs
4. Responsible Disclosure Guidelines
- Do not exploit or publicly disclose vulnerabilities before they are resolved.
- Do not access or modify customer data.
- Do not use automated scanners that could disrupt services.
- Limit testing to your own accounts or isolated environments.
We will acknowledge valid reports within 3 business days and keep you informed of progress until resolution.
5. Recognition
We value ethical researchers who help us maintain security. Contributors following this policy and providing valid reports may be recognized publicly on our Security Thanks page (unless anonymity is requested).
6. Legal Safe Harbor
We will not initiate legal action against individuals acting in good faith who comply with this Responsible Disclosure Policy and do not violate data privacy or access restrictions. Testing conducted under this policy is considered authorized under applicable laws.
7. Policy Updates
This document may be updated periodically as we improve our practices. The latest version will always be available at https://valuewayllc.com/security-policy.
Last Updated: October 28, 2025