Security & Responsible Disclosure
Security architecture principles and the channel for reporting vulnerabilities.
Last reviewed: 16 July 2026
Security model
Trusted PalmPay is designed around explicit trust zones: point of sale/edge, API and integration controls, identity/biometric services, payment/value orchestration, and bank/merchant systems. Boundaries and responsibilities are documented per deployment.
Device and channel trust
Expected controls include device inventory, unique channel identity, certificate lifecycle, mTLS, signed requests, nonce and replay protection, rate limits, secure boot/firmware controls where supported, and tamper-aware operations.
Biometric safeguards
Recommended controls include capture-quality validation, presentation-attack/liveness controls appropriate to the selected device, encrypted transfer, protected templates, separated storage, configurable thresholds, least privilege, re-enrollment and revocation.
Transaction integrity
The platform should enforce idempotency, order and merchant context binding, policy decisions, balance holds, debit/credit/reversal states, reconciliation, audit evidence and maker-checker controls for sensitive administration.
Application and infrastructure
Expected measures include secure SDLC, dependency and container scanning, secrets management, WAF/API gateway policies, network segmentation, centralized logging, alerting, backup/restore tests, vulnerability management, penetration tests and incident exercises.
No security guarantee
Security depends on the final hardware, firmware, configuration, integration, operations and shared-responsibility model. This page is not a certification or penetration-test report.
Report a vulnerability
Send a concise report to security@mobile-id.vn or info@mobile-id.vn with affected URL/component, impact, reproduction steps and safe evidence. Do not access other users' data, disrupt services, use social engineering or publicly disclose before coordinated remediation.
Acknowledgement
Mobile-ID will triage good-faith reports and coordinate next steps. Eligibility for recognition or rewards, if any, must be agreed in writing and is not promised by this page.
Standards and assurance scope
ISO/IEC 30107-3:2023, ISO/IEC 24745:2022, ISO/IEC 27001:2022 and OWASP API Security Top 10:2023 are used as scoped engineering and testing references. Certification or conformance must not be claimed without applicable independent evidence.
Level 9, Thuy Loi 4 Building, 286-288 Nguyen Xi Street, Binh Loi Trung Ward, Ho Chi Minh City
1900 6884
+84 28 3622 2982
info@mobile-id.vn