# Security at Planpacer

How Planpacer approaches security, and how to report vulnerabilities responsibly.

## Reporting a vulnerability

Report security issues to security@planpacer.com. A machine-readable policy is published at https://planpacer.com/.well-known/security.txt. You can expect an acknowledgement and follow-up while the report is investigated and fixed.

## Security practices

- Card payments are processed by Stripe; Planpacer does not store card numbers.
- Merchants connect their own Stripe account through Stripe Connect.
- Merchant dashboard access uses magic-link authentication with optional two-factor authentication.
- Customers view their payment schedule through private, unguessable links.

---

**Planpacer** is payment-plan software that collects deposits, instalments and final balances through Stripe, on a schedule the business sets. It is not a lender and not buy-now-pay-later. Pricing: concierge launch from EUR 199, then 1% per successful payment-plan transaction plus standard Stripe processing fees.

Canonical page: https://planpacer.com/security
More: https://planpacer.com/llms.txt
