New in Chargebee: Explore Reveal and understand your payment performance end-to-end.Try Now
Docschargebee docs
HomeBillingCPQPaymentsRevRecGrowthReveal
Support

Product Updates


  • Release Notes

Getting Started


  • Overview
  • Chargebee Billing Data Centers
  • Object Relationship Model
  • Understanding Sites
  • Chargebee Tech Glossary
  • Articles and FAQ

Implementing Chargebee


  • Implementation Guide
  • Go-live Checklist
  • Articles and FAQ

Agentic AI


  • Chargebee Copilot
  • Catalog Setup Assistant
  • MCP Servers

Developer Resources


  • Developer Resources Overview
  • API Explorer
  • Articles and FAQ

Chargebee Apps


  • Chargebee Apps CLI Developer Guide

Product Catalog


  • Product Catalog Overview
  • Coupons
  • Articles and FAQ

Subscriptions


  • Working with Subscriptions
  • Billing
  • Orders
  • Articles and FAQ

Customers


  • Managing Customers
  • Account Hierarchy
  • Email Notifications
  • Branding
  • Configure Multiple Languages
  • Articles and FAQ

Entitlements


  • Entitlements Overview
  • Features Overview
  • Feature Management
  • Managing Product Entitlements
  • Subscription Entitlements
  • Customer Entitlements
  • Grandfathering Entitlements
  • Articles and FAQ

Usage Based Billing


  • Overview
  • Use Cases
  • Setting up Usage Based Billing
  • Usage Alerts
  • Prepaid credits
  • Mid-term Subscription Changes
  • FAQs

Invoices and Credit Notes


  • Invoices
  • Credit Notes
  • Quotes [Legacy]
  • Transactions
  • Articles and FAQ

Taxes


  • Overview
  • Configuring Taxes
  • Country-specific Taxes
  • Articles and FAQ

E-Invoicing


  • Overview
  • Enabling E-Invoicing

Hosted Capabilities


  • Overview
  • Hosted Checkout
  • Hosted Self-Serve Portal
  • Hosted Pages Features
  • Additional Hosted Pages
  • Payment Components
  • Pricing Table
  • Mobile SDKs and Wrappers
  • Articles and FAQ

Site Configuration


  • Add Users & Assign Roles
  • Chargebee Notifications
  • Custom Fields & Metadata
  • Approvals
  • Mandatory Fields
  • File Attachments & Comments
  • Advanced Filter Options
  • Multicurrency Pricing
  • Multi-decimal Support
  • Configuring Reason Codes
  • Events and Webhooks
  • API Keys
  • OAuth Apps
  • Time Zone
  • Time Machine
  • Transfer Configurations
  • Articles and FAQ

Multi Business Entity


  • Multi Business Entity Overview
  • Customer Transfer Overview
  • Articles and FAQ

Mobile Subscriptions


  • Overview
  • Omnichannel Subscriptions
  • Omnichannel Subscriptions (Legacy)

Reports and Analytics


  • RevenueStory
  • Home Dashboard
  • Frequently Asked Questions
  • FAQs for Classic Reports Sunset
  • Articles and FAQ

Integrations


  • Sales
  • Customer Support and Success
  • Finance
  • Tax
  • E-Invoicing
  • Marketing
  • Stitch
  • Collaboration
  • Contract Management
  • Ecommerce Management
  • Articles and FAQ

Data Privacy & Security


  • Two Factor Authentication
  • SAML Single Sign-On
  • System for Cross-Domain Identity Management (SCIM)
  • EU-GDPR
  • Consent Management
  • Personal Data Management
  • Compliance Certificates
  • HIPAA Guidelines
  • PCI Recommendations and Integration Types
  • Articles and FAQ

Data Operations


  • Bulk Operations
  • Migration
  • Articles and FAQ
  1. Billing
  2. Data Privacy & Security
  3. Articles and FAQ
  4. Security Compliance
  1. Billing
  2. Data Privacy & Security
  3. Articles and FAQ
  4. Security Compliance

Does Chargebee support Vulnerability Assessment and Penetration Testing (VAPT)?

Problem Statement

You want to know whether Chargebee supports Vulnerability Assessment and Penetration Testing (VAPT) and how often security testing is performed.

Related Scenarios

  • Does Chargebee support VAPT security?
  • How often does Chargebee perform vulnerability scanning and patching?

Solution

Chargebee is committed to ensuring the confidentiality, integrity, and availability of the sensitive and confidential data of the customers it collects, stores, or transfers.

Vulnerability Assessment and Penetration Testing (VAPT) describes a broad range of security assessments designed to identify and help address cybersecurity exposures across an organization's IT estate. The evolving tools, tactics, and procedures used by cybercriminals to breach networks mean that it's essential to test your organization's cybersecurity regularly. VAPT helps protect your organization by providing visibility of security weaknesses and guidance to address them.

Types of scans

  • Internal VAPT (App & API)
  • External VAPT (App & API)
  • DAST (App & API)

Chargebee performs the VAPT assessment on a quarterly basis.

Chargebee periodically checks and applies patches for third-party software and services. As vulnerabilities are discovered, fixes are applied. Periodic vulnerability scanning is performed using the services of an authorized QSA.

In addition, Chargebee has an in-house security team that performs vulnerability scans on a monthly basis.

Each API endpoint is manually tested against vulnerabilities, which includes the following modules:

  • BOLA (Broken Object Level Authorization)
  • Broken User Authentication
  • Excessive Data Exposure
  • Lack of resources & rate limiting
  • Broken Function Level Authorization (BFLA)
  • Mass Assignment
  • Security Misconfiguration
  • Injection
  • Improper Asset Management
  • Insufficient Logging & Monitoring

Below are the major test cases validated when any module in the Chargebee product undergoes a security assessment:

  • Authentication
  • Authorization
  • Encryption
  • Information Leakage
  • Injection Attacks
  • Insecure Server Configuration
  • Session Management
  • Request Header based attacks
  • Others

Additional Information

For more information, see Vulnerability Scanning & Patching.

Related Articles

Was this article helpful?