Security
Report something safely.
Good-faith security research helps protect Melo users. Please report suspected vulnerabilities without including real financial records.
How to report
Email security@melo-money.com with the affected surface, reproduction steps, impact and any non-sensitive proof. Expect acknowledgement within two UK business days.
Please do not send
Do not include real statements, transaction history, bank credentials, authentication tokens, encryption keys or a Melo recovery secret. Use synthetic data and redact screenshots or logs.
Good-faith research
Keep testing proportionate, avoid privacy violations or service disruption, do not access another person's data, and give Melo reasonable time to investigate before disclosure. Good-faith work following these boundaries will not be treated as malicious.
Useful report types
Reports may cover the mobile app, encrypted local storage, Cloudflare services, authentication, billing verification, public website, dependencies or a privacy-boundary failure. General support requests belong at support@melo-money.com.