PCXWebsite security

Protecting a deliberately small public surface

The Prepaid Card X public site is static by design. Its purpose is to publish planning information without collecting card data or offering account access on the public domain.

01

Public-site boundaries

This website is not a cardholder portal, payment form, issuer system, or repository for Shopify customer exports. Visitors should never submit payment credentials, card data, account passwords, or private order files through public-site contact channels.

Operational systems and providers require their own access controls, review, monitoring, and incident procedures outside this website.

02

Responsible reporting

Send a concise security report to hello@prepaidcardx.com with the affected URL, observed behavior, time, and safe reproduction steps. Do not include live personal data or exploit a finding beyond what is needed to demonstrate it.

A report does not authorize disruption, social engineering, privacy invasion, persistence, or access to data belonging to others.

03

Program security is broader

A production prepaid card program needs security controls across Shopify data access, decision services, provider connections, recipient communications, support processes, and reconciliation evidence.

Use the program controls material to frame those responsibilities during design and provider diligence.