メインコンテンツへスキップ

Tiquoバグ報奨金プログラム

当社はプラットフォームの安全性を重視し、セキュリティ研究者の活動を尊重しています。手作業で確認された脆弱性の責任ある報告を歓迎します。

仕組み

1

Tiquo製品で潜在的なセキュリティ脆弱性を発見します。

2

セキュリティチームへ詳細な報告を送信します。

3

24時間以内に社内確認します。正式回答は後日になる場合があります。

4

当社チームが調査、再現、深刻度の分類を行います。

5

分類結果と報奨金額をお知らせします。

6

分類後30日以内に報奨金を支払います。

深刻度と報奨金は、現実の影響、悪用可能性、範囲をTiquoが個別に評価して決定します。

対象範囲

本プログラムの対象は次のとおりです。

  • tiquo.co
  • Tiquo APIエンドポイント
  • TiquoのiOS・Androidモバイルアプリ
  • tiquo.appのウェブアプリとダッシュボード
  • 認証および認可フロー
  • 決済およびデータ処理
  • Tiquoハードウェア

対象外

次の項目は報奨金の対象外です。

  • Tiquoが所有しない第三者サービスや連携
  • Tiquo従業員を狙うソーシャルエンジニアリングやフィッシング
  • サービス拒否攻撃(DoS/DDoS)
  • 直接的な安全上の影響がないスパムや速度制限
  • 機密情報や顧客情報を含まない独立プロジェクト
  • 古いブラウザーや基盤を必要とする脆弱性
  • すでに報告済み、または当社が把握している問題
  • 手作業で確認した動作証明のない、自動・推測的・AI生成の報告

報奨金の区分

報告は4段階に分類します。最終的な報奨金は、報告の品質、深刻度、利用者への潜在的影響によって決まります。

重大
£1,000 to £10,000

リモートコード実行、データベース全体へのアクセス、認証回避、決済侵害、大量の個人・金融データ流出など、全社に深刻な被害を与え得る脆弱性です。

£150 to £1,000

権限昇格、保存型XSS、IDOR、APIのアクセス制御不備など、個々の利用者や機密データに重大な影響を与える脆弱性です。

£50 to £150

反射型XSS、重要操作のCSRF、内部データの開示、CORS設定不備など、特定条件や利用者操作を必要とする脆弱性です。

£10 to £50

セキュリティヘッダー不足、詳細すぎるエラー、機密性の低いページのclickjacking、既知の悪用経路がない旧ソフトウェアなど、影響が限定的な問題です。

追加報奨金

特に明確な報告、広範な影響、独創的な攻撃連鎖、修正時の緊密な協力には、追加報奨金を支払う場合があります。

報告ガイドライン

迅速な調査のため、次の情報を含めてください。

  • 1
    脆弱性の明確な説明
  • 2
    再現手順
  • 3
    影響を受けるURL、エンドポイント、画面
  • 4
    テスト環境(ブラウザー、OS、端末)
  • 5
    可能な場合は画面画像や実証コード
  • 6
    潜在的影響に関するご自身の評価

1件の報告につき脆弱性は1つとし、異なる問題は別々に報告してください。

参加ルール

  • 1
    他の利用者のデータへアクセスしたり、変更・削除したりしないでください。
  • 2
    事前の書面承認なく、本番システムへ自動スキャンを実行しないでください。
  • 3
    脆弱性、報告、実証、関連情報を公開しないでください。
  • 4
    報告の作成にAIや大規模言語モデルを使用しないでください。ご自身の手作業による検証に基づく独自研究を求めます。推測的・未検証の報告は受理しません。
  • 5
    常に誠実に行動してください。

研究者の保護

誠実に行動しルールを守る研究者に対して、Tiquoは法的措置を取りません。本プログラムはTiquoの裁量で提供され、内容を変更・中止でき、当社の判断を最終決定とします。

連絡先

報告先:

security@tiquo.co

すべての報告を24時間以内に社内確認します。正式回答には時間を要する場合がありますが、10営業日以内に初期評価をお知らせします。状況確認の催促はお控えください。

© 2026 Tiquo. 「Tiquo」およびTiquoロゴはTiquo Ltd.の登録商標です。

GDPR · CCPA · PCI DSS · ICO · Cyber Essentials Certified · EU–US DPF · SOC 2 Type II (in progress) · ISO 27001 (in progress)

Security & Operational

  • 99.99% SLA Uptime
  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • AES-256 / TLS 1.3
  • Perfect Forward Secrecy (PFS)
  • HTTP Strict Transport Security (HSTS)
  • 99.999999999% (11 nines) data durability
  • Automated backups
  • DDoS protection
  • Web Application Firewall (WAF)
  • Zero Trust posture
  • Role-Based Access Control (RBAC)
  • Principle of Least Privilege
  • Secret scanning in CI
  • SBOM generation
  • Dependency supply-chain controls
  • 24/7 infrastructure monitoring
  • GDPR Article 22 safeguards
  • Data Protection Impact Assessments (DPIAs)
  • Records of Processing Activities (ROPA)
  • SAML 2.0 SSO
  • EASIE SSO
  • OAuth 2.0 / OpenID Connect (OIDC)
  • SCIM 2.0 provisioning
  • MFA / 2FA enforcement
  • Responsible disclosure / bug bounty programme

Privacy, Data Protection & Statutory Obligations

  • ICO Registered
  • UK Modern Slavery Act 2015 compliant
  • UK Public Interest Disclosure Act 1998 compliant
  • EU Article 27 Representative appointed (Paris, France)
  • Swiss FADP Article 14 Representative appointed
  • UK GDPR compliant
  • EU GDPR/DSGVO compliant
  • UK Data Protection Act 2018 compliant
  • Swiss revFADP compliant
  • CCPA / CPRA compliant (California)
  • VCDPA compliant (Virginia)
  • CPA compliant (Colorado)
  • CTDPA compliant (Connecticut)
  • TDPSA compliant (Texas)
  • OCPA compliant (Oregon)
  • MCDPA compliant (Montana)
  • FDBR compliant (Florida)
  • ICDPA compliant (Iowa)
  • ICDPA compliant (Indiana)
  • TIPA compliant (Tennessee)
  • DPDPA compliant (Delaware)
  • NJDPA compliant (New Jersey)
  • NHDPA compliant (New Hampshire)
  • NDPA compliant (Nebraska)
  • MCDPA compliant (Minnesota)
  • MODPA compliant (Maryland)
  • KCDPA compliant (Kentucky)
  • RIDTPPA compliant (Rhode Island)
  • Canada PIPEDA compliant
  • Quebec Law 25 compliant
  • Alberta PIPA compliant
  • British Columbia PIPA compliant
  • Singapore PDPA compliant
  • Hong Kong PDPO compliant
  • Brazil LGPD compliant
  • Japan APPI compliant
  • Australia Privacy Act / APPs compliant
  • India DPDPA 2023 compliant
  • Thailand PDPA compliant
  • Malaysia PDPA 2010 (as amended 2024) compliant
  • New Zealand Privacy Act 2020 compliant
  • South Africa POPIA compliant
  • UAE PDPL compliant
  • Mexico LFPDPPP compliant
  • Kenya Data Protection Act 2019 compliant
  • Ghana Data Protection Act 2012 compliant
  • Nigeria NDPA 2023 compliant
  • Indonesia PDP Law 2022 compliant
  • Philippines Data Privacy Act 2012 compliant

Global Fiscal & E-Invoicing

  • EN 16931 - EU e-invoicing core standard
  • UBL 2.1 - Universal Business Language
  • Austria - RKSV
  • Belgium - Peppol BIS 3.0 (B2B)
  • Czechia - fiscalization
  • Croatia - Fiscalization 2.0
  • Denmark - Peppol BIS 3.0 (B2B)
  • France - NF525 / LNE / Infocert, Factur-X / PDP, E-Reporting
  • Germany - KassenSichV / TSE, DSFinV-K, GoBD, E-Rechnung B2B (XRechnung / ZUGFeRD)
  • Hungary - Online Szamla
  • Italy - Scontrino, FatturaPA (via SDI)
  • Lithuania - i.SAF / i.MAS
  • Norway - Peppol BIS 3.0 (B2B), SAF-T
  • Poland - KSeF
  • Portugal - ATCUD/QR, SAF-T PT
  • Slovakia - eKasa
  • Slovenia - fiscalization (davcno potrjevanje)
  • Spain - FacturaE, SII, VeriFactu, TicketBAI
  • Sweden - SKVFS (certified cash registers)
  • Argentina - ARCA (Q4 2026)
  • Australia - Peppol PINT A-NZ (Q4 2026)
  • Brazil - NFe, NFCe, NFSe (Q4 2026)
  • Chile - SII Chile (Q4 2026)
  • Colombia - DIAN (Q4 2026)
  • Finland - Finvoice, TEAPPSXML (Q4 2026)
  • Japan - JP PINT (Peppol) (Q3 2026)
  • Malaysia - Peppol Malaysia (Q4 2026)
  • Mexico - CFDI (Q4 2026)
  • New Zealand - Peppol PINT A-NZ (Q4 2026)
  • Peru - SUNAT (Q4 2026)
  • Romania - Peppol (RO e-invoice) (Q4 2026)
  • Saudi Arabia - ZATCA (Q4 2026)
  • Singapore - Peppol BIS 3.0 (Q4 2026)
  • United Arab Emirates - Peppol (5C) (Q4 2026)

Standards & Frameworks

  • Cyber Essentials Certified
  • SOC 2 Type II - audit in progress
  • ISO/IEC 27001 - audit in progress
  • NIST Cybersecurity Framework - aligned
  • NIST Privacy Framework - aligned
  • NIST SP 800-53 / 800-63 / 800-63B - aligned
  • NIST AI Risk Management Framework - aligned
  • CIS Critical Security Controls / CIS Benchmarks - aligned
  • OWASP ASVS & OWASP Top Ten - aligned
  • ISO 25010 (quality) - aligned
  • ISO 31000 (risk) - aligned
  • ITIL - aligned
  • W3C Web Standards - aligned
  • OpenAPI Standard - aligned
  • DevSecOps practices - aligned
  • ePrivacy Directive - aligned
  • EU Whistleblowing Directive (2019/1937) - aligned

Payments Compliance

  • PCI DSS Level 1
  • PSD2 / Strong Customer Authentication
  • 3D Secure (3DS)
  • EMVCo Level 1 & 2
  • AML / KYC controls
  • Sanctions screening (OFAC, UN, EU, HMT)

International Data Transfer Mechanisms

  • EU-US Data Privacy Framework
  • EU Standard Contractual Clauses (Decision 2021/914) - Modules 2 & 3
  • UK International Data Transfer Agreement (IDTA) + ICO Addendum
  • Swiss FDPIC-recognised transfer mechanisms
  • APEC Cross-Border Privacy Rules (CBPR)

Accessibility Compliance

  • ADA (Americans with Disabilities Act) - aligned
  • European Accessibility Act (EAA) 2025 - aligned
  • WCAG 2.2 - aligned
  • EN 301 549 - aligned
  • WAI-ARIA - aligned

ホテル、スパ、クラス、イベント、レストランなどのための統合プラットフォーム。

Tiquo Ltd
ロンドン、イギリス

LinkedInTop Performer Spring

Cookieを使用しています

当サイトでは、お客様の体験を向上させるためにCookieを使用しています。閲覧を続けることで、Cookieの使用に同意したことになります。

詳細を見る