Trust & Security
How PayProbe handles your data
PayProbe is built for payment QA, development, and certification prep using test data only. Sensitive calculations run locally in your browser, and we are designed so that card numbers, keys, PINs, and cryptograms never reach our servers.
PayProbe is designed for payment QA and development using test data only. Sensitive calculations run locally where possible, and PayProbe does not store PAN, CVV, PIN, cryptographic keys, PIN blocks, or generated cryptograms.
1 Data handling
Test data only
Tools are for development, QA, and certification prep. Do not enter real PANs, CVVs, PINs, production keys, or live cardholder data.
Browser-local processing
Cryptographic and card calculations run client-side in your browser. There is no backend that receives your inputs.
No storage
We do not persist your PAN, CVV, PIN blocks, cryptographic keys, or generated cryptograms — on a server or anywhere else.
Your inputs are never tracked
To fund free tools we show Google AdSense ads and measure aggregate traffic with Cloudflare Web Analytics (cookieless). These operate at the page level only — they never capture the card data, keys, or values you enter into a tool.
2 Security controls
- HTTPS-only with HSTS (includeSubDomains, preload-eligible).
- Content-Security-Policy restricting resources to our own origin plus a vetted allowlist (Google AdSense and Cloudflare Analytics).
- Hardened response headers: X-Content-Type-Options, X-Frame-Options / frame-ancestors, Referrer-Policy, Permissions-Policy, Cross-Origin-Opener-Policy.
- No accounts, logins, or server-side sessions for the free tools — nothing sensitive to breach.
- Dependencies kept current and monitored for known vulnerabilities.
- A published vulnerability disclosure channel (security.txt).
3 Verify it yourself
We would rather you check than take our word for it. Run any of these independent scanners against payprobe.io:
We have not yet completed a formal third-party penetration test or SOC 2 / ISO 27001 audit. When we do, the attestations will be listed here. We do not use purchased “trust badges.”
4 Responsible disclosure
Found a vulnerability? Email [email protected]. We aim to acknowledge reports within two business days and will coordinate a disclosure timeline with you. Our machine-readable policy lives at /.well-known/security.txt (RFC 9116).
5 Standards we reference
PayProbe's tools implement and cite recognized payment and security standards, including EMV (EMVCo specifications), ISO 8583 messaging, ISO 4217 currencies, ISO 7813 track data, ANSI X9 / TR-31 & TR-34 key management, and PCI DSS guidance for safe handling of test data. See our Standards reference and learning guides.
6 Responsible use
PayProbe is intended for development, QA, and certification preparation. Do not enter real PANs, CVVs, PINs, production keys, or live cardholder data into any tool. Use scheme test cards and your own test vectors. Continued use indicates acceptance of our Terms of Service and Privacy Policy.