Tiquo Bug Bounty Program
At Tiquo, we take the security of our platform seriously. We value the work of security researchers and welcome responsible disclosure of vulnerabilities. If you discover a security issue, we'd like to hear from you.
How It Works
You discover a potential security vulnerability in a Tiquo product.
You submit a detailed report to our security team.
Εξετάζουμε την αναφορά σας εσωτερικά εντός 24 ωρών. Η επίσημη απάντησή μας μπορεί να ακολουθήσει αργότερα.
Our team investigates, reproduces, and classifies the severity of the issue.
We notify you of our classification and the reward amount.
Payment is issued within 30 days of classification.
All severity classifications and reward amounts are determined by Tiquo after submission. We assess every report individually based on the real-world impact, exploitability, and scope of the vulnerability.
What's in Scope
Our bug bounty program covers the following:
- tiquo.co
- Tiquo API endpoints
- Tiquo iOS and Android mobile applications
- tiquo.app webapp / dashboard
- Authentication and authorization flows
- Payment and data handling processes
- Tiquo hardware
What's Out of Scope
The following are not eligible for rewards:
- Third-party services or integrations not owned by Tiquo
- Social engineering or phishing attacks against Tiquo employees
- Denial of service (DoS/DDoS) attacks
- Spam or rate-limiting issues with no direct security impact
- Isolated projects which have no sensitive data or customer information
- Vulnerabilities requiring outdated browsers or platforms
- Issues that have already been reported or are already known to us
- Αναφορές που έχουν δημιουργηθεί από AI, αυτοματοποιημένες ή υποθετικές αναφορές που δεν βασίζονται σε χειροκίνητα επαληθευμένο, λειτουργικό proof of concept.
Reward Tiers
We classify all submissions into four severity levels. The final reward is determined by Tiquo based on the quality of the report, the severity of the vulnerability, and the potential impact to our users.
Vulnerabilities that could cause severe, company-wide damage. This includes remote code execution, full database access, authentication bypass granting access to all user accounts, payment system compromise, or mass exfiltration of personal or financial data.
Significant vulnerabilities that affect individual users or expose sensitive data. This includes privilege escalation, stored cross-site scripting in sensitive contexts, insecure direct object references exposing other users' data, or broken access controls on API endpoints.
Vulnerabilities that require specific conditions or user interaction to exploit. This includes reflected cross-site scripting, cross-site request forgery on sensitive actions, information disclosure of internal system data, or misconfigured CORS policies.
Minor issues with limited security impact. This includes missing security headers, verbose error messages exposing internal details, clickjacking on non-sensitive pages, or outdated software versions with no known exploit path.
Bonus Awards
Tiquo reserves the right to award bonuses above the stated ranges for exceptional reports. Factors that may qualify a submission for a bonus include particularly well-written reports with clear reproduction steps, vulnerabilities with widespread impact across multiple systems, creative exploitation chains that reveal deeper architectural issues, or researchers who work closely with our team during remediation. Bonus amounts are determined on a case-by-case basis.
Submission Guidelines
To help us investigate quickly, please include the following in your report:
- 1A clear description of the vulnerability
- 2Step-by-step reproduction instructions
- 3The affected URL, endpoint, or application screen
- 4Your testing environment (browser, OS, device)
- 5Screenshots or proof-of-concept code where possible
- 6Your assessment of the potential impact
Please submit one vulnerability per report. If you've found multiple issues, send a separate report for each.
Rules of Engagement
- 1Do not access, modify, or delete data belonging to other users.
- 2Do not run automated scanning tools against production systems without prior written approval from Tiquo.
- 3Μη δημοσιοποιείτε οποιαδήποτε ευπάθεια, αναφορά, proof of concept ή σχετικές λεπτομέρειες οποιαδήποτε στιγμή.
- 4Μη χρησιμοποιείτε εργαλεία AI ή μεγάλα γλωσσικά μοντέλα για να δημιουργήσετε ή να γράψετε τις αναφορές σας. Θέλουμε πρωτότυπη έρευνα βασισμένη στις δικές σας πρακτικές δοκιμές. Υποβολές που φαίνεται να έχουν δημιουργηθεί από AI, είναι υποθετικές ή δεν βασίζονται σε πραγματική, χειροκίνητα επαληθευμένη ευπάθεια θα απορρίπτονται χωρίς έλεγχο και μπορεί να οδηγήσουν σε απομάκρυνση από το πρόγραμμα.
- 5Act in good faith at all times.
Safe Harbour
Οι ερευνητές ασφαλείας που ενεργούν καλόπιστα και ακολουθούν τους παραπάνω κανόνες δεν θα αντιμετωπίσουν νομικές ενέργειες από την Tiquo. Θεωρούμε την υπεύθυνη έρευνα ασφαλείας που διεξάγεται σύμφωνα με αυτήν την πολιτική ως εξουσιοδοτημένη δραστηριότητα. Δεν θα επιδιώξουμε αστικές ή ποινικές ενέργειες κατά ερευνητών που συμμορφώνονται με αυτό το πρόγραμμα. Το πρόγραμμα προσφέρεται κατά τη διακριτική ευχέρεια της Tiquo. Διατηρούμε το δικαίωμα να καθορίζουμε την επιλεξιμότητα, τη σοβαρότητα και την ανταμοιβή για οποιαδήποτε υποβολή, καθώς και να τροποποιούμε, να αναστέλλουμε ή να τερματίζουμε το πρόγραμμα οποιαδήποτε στιγμή. Όλες οι αποφάσεις της Tiquo είναι τελικές και η συμμετοχή δεν δημιουργεί κανένα συμβατικό δικαίωμα σε ανταμοιβή.
Contact
Submit your reports to:
security@tiquo.coΚάθε αναφορά εξετάζεται εσωτερικά εντός 24 ωρών από την υποβολή. Λάβετε υπόψη ότι η επίσημη απάντησή μας μπορεί να χρειαστεί περισσότερο χρόνο, καθώς η ταξινόμηση εξαρτάται από την πολυπλοκότητα του ζητήματος και τον χρόνο που απαιτείται για την αναπαραγωγή και αξιολόγησή του. Μην στέλνετε μηνύματα υπενθύμισης για την κατάσταση της αναφοράς σας. Τα μηνύματα υπενθύμισης καθυστερούν την εξέταση για όλους. Θα επικοινωνήσουμε μαζί σας μόλις έχουμε ενημέρωση, και μπορείτε να αναμένετε μια αρχική αξιολόγηση εντός 10 εργάσιμων ημερών.