Vulnerability disclosure
The security of our systems and the protection of our customers is our highest priority. We encourage responsible security research and welcome reports of potential vulnerabilities in our products, services, or infrastructure.
If you believe you have discovered a security vulnerability, please report it to us as soon as possible.
How to report a vulnerability
To report a potential security vulnerability, email us at:
📨 support@pepperstone.com
(This address is monitored and escalated to the relevant security teams.)
When submitting a report, please include:
- A clear explanation of the potential security vulnerability
- Details of affected products, services, or endpoints (where known)
- Steps to reproduce the issue
- Proof-of-concept code or screenshots (if applicable)
- Any test accounts or data used during testing
- Your contact details so our team can follow up if needed
Our expectations
We ask that responsible researchers:
- Do not access, modify, or delete data
- Avoid actions that may negatively impact performance or availability
- Refrain from disclosing details of the vulnerability publicly until we provide written permission
- Follow applicable laws when conducting research
What you can expect from us
Upon receiving your report:
- We will acknowledge receipt of your submission
- Our security team will investigate the issue and determine severity
- We may request additional information to support reproduction and validation
- We will notify you once the vulnerability has been resolved or if further clarification is needed
We deeply appreciate the efforts of the security community in helping us safeguard our users and our platform.