PayBees
← Home

Security & Responsible Disclosure

Last updated: 8 May 2026 · Jointly operated by DevServe HK Limited (Hong Kong) and IC AG (Geneva, Switzerland)

Security is foundational to PayBees. This page describes the technical safeguards we apply to the website and the process for reporting a security issue to us. PayBees is jointly operated by DevServe HK Limited (Hong Kong) and IC AG (Geneva, Switzerland); a report to either entity reaches both security teams.

Our security posture

PayBees follows OWASP best-practice guidance for public-facing web applications:

Production roadmap

Before any production payment processing, the PayBees platform will operate under SOC 2 Type II controls and applicable payment-services licences in each jurisdiction we serve, including, where relevant:

Responsible disclosure

Found a security issue? Please report it privately to security@paybees.money. We will not pursue legal action against good-faith researchers who follow this policy.

What's in scope

What's out of scope

What to include in your report

Our commitments

Safe harbour

Provided that your testing is consistent with this policy, follows applicable law, and is limited to in-scope assets, DevServe HK Limited and IC AG (jointly) will:

Safe harbour does not apply to testing that violates third-party rights, accesses or copies third-party data, or causes service degradation.

Contact

Reports to either address reach the joint security team:

DevServe HK Limited — Security Team
Unit 1411, 14/F, COSCO Tower, 183 Queen's Road Central, Sheung Wan, Hong Kong

IC AG — Security Team
Geneva, Switzerland

Email: security@paybees.money