メインコンテンツへスキップ

Tiquo Bug Bounty Program

At Tiquo, we take the security of our platform seriously. We value the work of security researchers and welcome responsible disclosure of vulnerabilities. If you discover a security issue, we'd like to hear from you.

How It Works

1

You discover a potential security vulnerability in a Tiquo product.

2

You submit a detailed report to our security team.

3

報告は24時間以内に社内で確認します。正式な回答は後日となる場合があります。

4

Our team investigates, reproduces, and classifies the severity of the issue.

5

We notify you of our classification and the reward amount.

6

Payment is issued within 30 days of classification.

All severity classifications and reward amounts are determined by Tiquo after submission. We assess every report individually based on the real-world impact, exploitability, and scope of the vulnerability.

What's in Scope

Our bug bounty program covers the following:

  • tiquo.co
  • Tiquo API endpoints
  • Tiquo iOS and Android mobile applications
  • tiquo.app webapp / dashboard
  • Authentication and authorization flows
  • Payment and data handling processes
  • Tiquo hardware

What's Out of Scope

The following are not eligible for rewards:

  • Third-party services or integrations not owned by Tiquo
  • Social engineering or phishing attacks against Tiquo employees
  • Denial of service (DoS/DDoS) attacks
  • Spam or rate-limiting issues with no direct security impact
  • Isolated projects which have no sensitive data or customer information
  • Vulnerabilities requiring outdated browsers or platforms
  • Issues that have already been reported or are already known to us
  • 手動で検証された動作する proof of concept に基づかない、AI生成、自動化、または推測的な報告。

Reward Tiers

We classify all submissions into four severity levels. The final reward is determined by Tiquo based on the quality of the report, the severity of the vulnerability, and the potential impact to our users.

Critical
£1,000 to £10,000

Vulnerabilities that could cause severe, company-wide damage. This includes remote code execution, full database access, authentication bypass granting access to all user accounts, payment system compromise, or mass exfiltration of personal or financial data.

High
£150 to £1,000

Significant vulnerabilities that affect individual users or expose sensitive data. This includes privilege escalation, stored cross-site scripting in sensitive contexts, insecure direct object references exposing other users' data, or broken access controls on API endpoints.

Medium
£50 to £150

Vulnerabilities that require specific conditions or user interaction to exploit. This includes reflected cross-site scripting, cross-site request forgery on sensitive actions, information disclosure of internal system data, or misconfigured CORS policies.

Low
£10 to £50

Minor issues with limited security impact. This includes missing security headers, verbose error messages exposing internal details, clickjacking on non-sensitive pages, or outdated software versions with no known exploit path.

Bonus Awards

Tiquo reserves the right to award bonuses above the stated ranges for exceptional reports. Factors that may qualify a submission for a bonus include particularly well-written reports with clear reproduction steps, vulnerabilities with widespread impact across multiple systems, creative exploitation chains that reveal deeper architectural issues, or researchers who work closely with our team during remediation. Bonus amounts are determined on a case-by-case basis.

Submission Guidelines

To help us investigate quickly, please include the following in your report:

  • 1
    A clear description of the vulnerability
  • 2
    Step-by-step reproduction instructions
  • 3
    The affected URL, endpoint, or application screen
  • 4
    Your testing environment (browser, OS, device)
  • 5
    Screenshots or proof-of-concept code where possible
  • 6
    Your assessment of the potential impact

Please submit one vulnerability per report. If you've found multiple issues, send a separate report for each.

Rules of Engagement

  • 1
    Do not access, modify, or delete data belonging to other users.
  • 2
    Do not run automated scanning tools against production systems without prior written approval from Tiquo.
  • 3
    脆弱性、報告、proof of concept、または関連する詳細を、いかなる時点でも公開しないでください。
  • 4
    報告の生成または作成にAIツールや大規模言語モデルを使用しないでください。私たちは、あなた自身の実地テストに基づく独自の調査を求めています。AI生成、推測的、または実際に手動で検証された脆弱性に基づいていないと思われる提出は、レビューなしで却下され、プログラムから除外される場合があります。
  • 5
    Act in good faith at all times.

Safe Harbour

善意で行動し、上記のルールに従うセキュリティ研究者に対して、Tiquoが法的措置を取ることはありません。当社は、このポリシーに沿って実施される責任あるセキュリティ調査を、許可された活動とみなします。このプログラムを遵守する研究者に対して、民事または刑事上の措置を追求することはありません。本プログラムはTiquoの裁量により提供されます。当社は、あらゆる提出について適格性、深刻度、報酬を決定し、またいつでもプログラムを変更、一時停止、終了する権利を留保します。Tiquoによるすべての決定は最終的なものであり、参加によって報酬に対する契約上の権利が生じるものではありません。

Contact

Submit your reports to:

security@tiquo.co

すべての報告は提出から24時間以内に社内で確認されます。ただし、分類は問題の複雑さと再現・評価に必要な時間に左右されるため、正式な回答にはさらに時間がかかる場合があります。報告の状況を確認するためのフォローアップメッセージは送らないでください。催促メールは全員のレビューを遅らせます。更新があり次第ご連絡します。初期評価は10営業日以内に行われる予定です。

Cookieを使用しています

当サイトでは、お客様の体験を向上させるためにCookieを使用しています。閲覧を続けることで、Cookieの使用に同意したことになります。

詳細を見る