Skip to main content

Tiquo Bug Bounty Program

At Tiquo, we take the security of our platform seriously. We value the work of security researchers and welcome responsible disclosure of vulnerabilities. If you discover a security issue, we'd like to hear from you.

How It Works

1

You discover a potential security vulnerability in a Tiquo product.

2

You submit a detailed report to our security team.

3

We review your report internally within 24 hours. Our formal response to you may follow later.

4

Our team investigates, reproduces, and classifies the severity of the issue.

5

We notify you of our classification and the reward amount.

6

Payment is issued within 30 days of classification.

All severity classifications and reward amounts are determined by Tiquo after submission. We assess every report individually based on the real-world impact, exploitability, and scope of the vulnerability.

What's in Scope

Our bug bounty program covers the following:

  • tiquo.co
  • Tiquo API endpoints
  • Tiquo iOS and Android mobile applications
  • tiquo.app webapp / dashboard
  • Authentication and authorization flows
  • Payment and data handling processes
  • Tiquo hardware

What's Out of Scope

The following are not eligible for rewards:

  • Third-party services or integrations not owned by Tiquo
  • Social engineering or phishing attacks against Tiquo employees
  • Denial of service (DoS/DDoS) attacks
  • Spam or rate-limiting issues with no direct security impact
  • Isolated projects which have no sensitive data or customer information
  • Vulnerabilities requiring outdated browsers or platforms
  • Issues that have already been reported or are already known to us
  • AI-generated, automated, or speculative reports not based on a manually verified, working proof of concept.

Reward Tiers

We classify all submissions into four severity levels. The final reward is determined by Tiquo based on the quality of the report, the severity of the vulnerability, and the potential impact to our users.

Critical
£1,000 to £10,000

Vulnerabilities that could cause severe, company-wide damage. This includes remote code execution, full database access, authentication bypass granting access to all user accounts, payment system compromise, or mass exfiltration of personal or financial data.

High
£150 to £1,000

Significant vulnerabilities that affect individual users or expose sensitive data. This includes privilege escalation, stored cross-site scripting in sensitive contexts, insecure direct object references exposing other users' data, or broken access controls on API endpoints.

Medium
£50 to £150

Vulnerabilities that require specific conditions or user interaction to exploit. This includes reflected cross-site scripting, cross-site request forgery on sensitive actions, information disclosure of internal system data, or misconfigured CORS policies.

Low
£10 to £50

Minor issues with limited security impact. This includes missing security headers, verbose error messages exposing internal details, clickjacking on non-sensitive pages, or outdated software versions with no known exploit path.

Bonus Awards

Tiquo reserves the right to award bonuses above the stated ranges for exceptional reports. Factors that may qualify a submission for a bonus include particularly well-written reports with clear reproduction steps, vulnerabilities with widespread impact across multiple systems, creative exploitation chains that reveal deeper architectural issues, or researchers who work closely with our team during remediation. Bonus amounts are determined on a case-by-case basis.

Submission Guidelines

To help us investigate quickly, please include the following in your report:

  • 1
    A clear description of the vulnerability
  • 2
    Step-by-step reproduction instructions
  • 3
    The affected URL, endpoint, or application screen
  • 4
    Your testing environment (browser, OS, device)
  • 5
    Screenshots or proof-of-concept code where possible
  • 6
    Your assessment of the potential impact

Please submit one vulnerability per report. If you've found multiple issues, send a separate report for each.

Rules of Engagement

  • 1
    Do not access, modify, or delete data belonging to other users.
  • 2
    Do not run automated scanning tools against production systems without prior written approval from Tiquo.
  • 3
    Do not publicly disclose any vulnerability, report, proof of concept, or related details at any time.
  • 4
    Do not use AI tools or large language models to generate or write your reports. We want original research based on your own hands-on testing. Submissions that appear to be AI-generated, speculative, or not based on a genuine, manually verified vulnerability will be rejected without review and may result in removal from the program.
  • 5
    Act in good faith at all times.

Safe Harbour

Security researchers who act in good faith and follow the rules above will not face legal action from Tiquo. We consider responsible security research conducted in line with this policy to be authorised activity. We will not pursue civil or criminal action against researchers who comply with this program. This program is offered at Tiquo's discretion. We reserve the right to determine eligibility, severity, and reward for any submission, and to amend, suspend, or end the program at any time. All decisions made by Tiquo are final, and participation does not create any contractual entitlement to a reward.

Contact

Submit your reports to:

security@tiquo.co

Every report is reviewed internally within 24 hours of submission. Please note that our formal response to you may take longer, as classification depends on the complexity of the issue and the time needed to reproduce and assess it. Please do not send follow-up messages chasing the status of your report. Chaser emails slow down the review for everyone. We will contact you as soon as we have an update, and you can expect an initial assessment within 10 business days.

© 2026 Tiquo. "Tiquo" and the Tiquo logo are registered trademarks of Tiquo Ltd.

GDPR · CCPA · PCI DSS · ICO · Cyber Essentials Certified · EU–US DPF · SOC 2 Type II (in progress) · ISO 27001 (in progress)

Security & Operational

  • 99.99% SLA Uptime
  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • AES-256 / TLS 1.3
  • Perfect Forward Secrecy (PFS)
  • HTTP Strict Transport Security (HSTS)
  • 99.999999999% (11 nines) data durability
  • Automated backups
  • DDoS protection
  • Web Application Firewall (WAF)
  • Zero Trust posture
  • Role-Based Access Control (RBAC)
  • Principle of Least Privilege
  • Secret scanning in CI
  • SBOM generation
  • Dependency supply-chain controls
  • 24/7 infrastructure monitoring
  • GDPR Article 22 safeguards
  • Data Protection Impact Assessments (DPIAs)
  • Records of Processing Activities (ROPA)
  • SAML 2.0 SSO
  • EASIE SSO
  • OAuth 2.0 / OpenID Connect (OIDC)
  • SCIM 2.0 provisioning
  • MFA / 2FA enforcement
  • Responsible disclosure / bug bounty programme

Privacy, Data Protection & Statutory Obligations

  • ICO Registered
  • UK Modern Slavery Act 2015 compliant
  • UK Public Interest Disclosure Act 1998 compliant
  • EU Article 27 Representative appointed (Paris, France)
  • Swiss FADP Article 14 Representative appointed
  • UK GDPR compliant
  • EU GDPR/DSGVO compliant
  • UK Data Protection Act 2018 compliant
  • Swiss revFADP compliant
  • CCPA / CPRA compliant (California)
  • VCDPA compliant (Virginia)
  • CPA compliant (Colorado)
  • CTDPA compliant (Connecticut)
  • TDPSA compliant (Texas)
  • OCPA compliant (Oregon)
  • MCDPA compliant (Montana)
  • FDBR compliant (Florida)
  • ICDPA compliant (Iowa)
  • ICDPA compliant (Indiana)
  • TIPA compliant (Tennessee)
  • DPDPA compliant (Delaware)
  • NJDPA compliant (New Jersey)
  • NHDPA compliant (New Hampshire)
  • NDPA compliant (Nebraska)
  • MCDPA compliant (Minnesota)
  • MODPA compliant (Maryland)
  • KCDPA compliant (Kentucky)
  • RIDTPPA compliant (Rhode Island)
  • Canada PIPEDA compliant
  • Quebec Law 25 compliant
  • Alberta PIPA compliant
  • British Columbia PIPA compliant
  • Singapore PDPA compliant
  • Hong Kong PDPO compliant
  • Brazil LGPD compliant
  • Japan APPI compliant
  • Australia Privacy Act / APPs compliant
  • India DPDPA 2023 compliant
  • Thailand PDPA compliant
  • Malaysia PDPA 2010 (as amended 2024) compliant
  • New Zealand Privacy Act 2020 compliant
  • South Africa POPIA compliant
  • UAE PDPL compliant
  • Mexico LFPDPPP compliant
  • Kenya Data Protection Act 2019 compliant
  • Ghana Data Protection Act 2012 compliant
  • Nigeria NDPA 2023 compliant
  • Indonesia PDP Law 2022 compliant
  • Philippines Data Privacy Act 2012 compliant

Global Fiscal & E-Invoicing

  • EN 16931 - EU e-invoicing core standard
  • UBL 2.1 - Universal Business Language
  • Austria - RKSV
  • Belgium - Peppol BIS 3.0 (B2B)
  • Czechia - fiscalization
  • Croatia - Fiscalization 2.0
  • Denmark - Peppol BIS 3.0 (B2B)
  • France - NF525 / LNE / Infocert, Factur-X / PDP, E-Reporting
  • Germany - KassenSichV / TSE, DSFinV-K, GoBD, E-Rechnung B2B (XRechnung / ZUGFeRD)
  • Hungary - Online Szamla
  • Italy - Scontrino, FatturaPA (via SDI)
  • Lithuania - i.SAF / i.MAS
  • Norway - Peppol BIS 3.0 (B2B), SAF-T
  • Poland - KSeF
  • Portugal - ATCUD/QR, SAF-T PT
  • Slovakia - eKasa
  • Slovenia - fiscalization (davcno potrjevanje)
  • Spain - FacturaE, SII, VeriFactu, TicketBAI
  • Sweden - SKVFS (certified cash registers)
  • Argentina - ARCA (Q4 2026)
  • Australia - Peppol PINT A-NZ (Q4 2026)
  • Brazil - NFe, NFCe, NFSe (Q4 2026)
  • Chile - SII Chile (Q4 2026)
  • Colombia - DIAN (Q4 2026)
  • Finland - Finvoice, TEAPPSXML (Q4 2026)
  • Japan - JP PINT (Peppol) (Q3 2026)
  • Malaysia - Peppol Malaysia (Q4 2026)
  • Mexico - CFDI (Q4 2026)
  • New Zealand - Peppol PINT A-NZ (Q4 2026)
  • Peru - SUNAT (Q4 2026)
  • Romania - Peppol (RO e-invoice) (Q4 2026)
  • Saudi Arabia - ZATCA (Q4 2026)
  • Singapore - Peppol BIS 3.0 (Q4 2026)
  • United Arab Emirates - Peppol (5C) (Q4 2026)

Standards & Frameworks

  • Cyber Essentials Certified
  • SOC 2 Type II - audit in progress
  • ISO/IEC 27001 - audit in progress
  • NIST Cybersecurity Framework - aligned
  • NIST Privacy Framework - aligned
  • NIST SP 800-53 / 800-63 / 800-63B - aligned
  • NIST AI Risk Management Framework - aligned
  • CIS Critical Security Controls / CIS Benchmarks - aligned
  • OWASP ASVS & OWASP Top Ten - aligned
  • ISO 25010 (quality) - aligned
  • ISO 31000 (risk) - aligned
  • ITIL - aligned
  • W3C Web Standards - aligned
  • OpenAPI Standard - aligned
  • DevSecOps practices - aligned
  • ePrivacy Directive - aligned
  • EU Whistleblowing Directive (2019/1937) - aligned

Payments Compliance

  • PCI DSS Level 1
  • PSD2 / Strong Customer Authentication
  • 3D Secure (3DS)
  • EMVCo Level 1 & 2
  • AML / KYC controls
  • Sanctions screening (OFAC, UN, EU, HMT)

International Data Transfer Mechanisms

  • EU-US Data Privacy Framework
  • EU Standard Contractual Clauses (Decision 2021/914) - Modules 2 & 3
  • UK International Data Transfer Agreement (IDTA) + ICO Addendum
  • Swiss FDPIC-recognised transfer mechanisms
  • APEC Cross-Border Privacy Rules (CBPR)

Accessibility Compliance

  • ADA (Americans with Disabilities Act) - aligned
  • European Accessibility Act (EAA) 2025 - aligned
  • WCAG 2.2 - aligned
  • EN 301 549 - aligned
  • WAI-ARIA - aligned

A single platform for hotels, spas, classes, events, restaurants, and more.

Tiquo Ltd
London, UK

LinkedInTop Performer Spring

We use cookies

We use cookies to improve your experience on our site. By continuing to browse, you agree to our use of cookies.

Learn more