Last updated September 25, 2026
Vivid Productions, LLC, doing business as MobileTopup.com, values the work of independent security researchers in keeping our users safe. This page explains how to report a suspected security vulnerability in our systems and what to expect from us in response.
The following are in scope for vulnerability reports:
Out of scope: dev.mobiletopup.com and any other staging/development subdomain are explicitly out of scope — they run against live production data and must not be targeted. Also out of scope: denial-of-service testing, spam or social engineering against our staff or users, physical security testing, and automated vulnerability scanning that generates significant traffic without prior coordination with us.
Please email [email protected] with one issue per email. To help us triage and reproduce your report quickly, please include:
Please do not include real customer data, payment card numbers, or account passwords in your report.
We will acknowledge receipt of your report within 3 business days. We will keep you informed of our progress as we investigate and remediate confirmed issues, and we will let you know once a fix has been deployed.
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy: testing only in-scope systems, avoiding harm to our users and services, not accessing or exfiltrating more data than necessary to demonstrate an issue, and reporting findings to us promptly and privately before any public disclosure.
We do not currently offer a paid bug bounty program. We are happy to credit researchers who report valid, previously-unknown vulnerabilities, with their permission, once a fix has shipped.
Email [email protected]. A machine-readable copy of this contact information is published at /.well-known/security.txt per RFC 9116.