본문으로 건너뛰기

Tiquo Bug Bounty Program

At Tiquo, we take the security of our platform seriously. We value the work of security researchers and welcome responsible disclosure of vulnerabilities. If you discover a security issue, we'd like to hear from you.

How It Works

1

You discover a potential security vulnerability in a Tiquo product.

2

You submit a detailed report to our security team.

3

제출하신 보고서는 24시간 이내에 내부 검토합니다. 공식 답변은 이후에 전달될 수 있습니다.

4

Our team investigates, reproduces, and classifies the severity of the issue.

5

We notify you of our classification and the reward amount.

6

Payment is issued within 30 days of classification.

All severity classifications and reward amounts are determined by Tiquo after submission. We assess every report individually based on the real-world impact, exploitability, and scope of the vulnerability.

What's in Scope

Our bug bounty program covers the following:

  • tiquo.co
  • Tiquo API endpoints
  • Tiquo iOS and Android mobile applications
  • tiquo.app webapp / dashboard
  • Authentication and authorization flows
  • Payment and data handling processes
  • Tiquo hardware

What's Out of Scope

The following are not eligible for rewards:

  • Third-party services or integrations not owned by Tiquo
  • Social engineering or phishing attacks against Tiquo employees
  • Denial of service (DoS/DDoS) attacks
  • Spam or rate-limiting issues with no direct security impact
  • Isolated projects which have no sensitive data or customer information
  • Vulnerabilities requiring outdated browsers or platforms
  • Issues that have already been reported or are already known to us
  • 수동으로 검증된 작동하는 proof of concept에 기반하지 않은 AI 생성, 자동화 또는 추측성 보고서.

Reward Tiers

We classify all submissions into four severity levels. The final reward is determined by Tiquo based on the quality of the report, the severity of the vulnerability, and the potential impact to our users.

Critical
£1,000 to £10,000

Vulnerabilities that could cause severe, company-wide damage. This includes remote code execution, full database access, authentication bypass granting access to all user accounts, payment system compromise, or mass exfiltration of personal or financial data.

High
£150 to £1,000

Significant vulnerabilities that affect individual users or expose sensitive data. This includes privilege escalation, stored cross-site scripting in sensitive contexts, insecure direct object references exposing other users' data, or broken access controls on API endpoints.

Medium
£50 to £150

Vulnerabilities that require specific conditions or user interaction to exploit. This includes reflected cross-site scripting, cross-site request forgery on sensitive actions, information disclosure of internal system data, or misconfigured CORS policies.

Low
£10 to £50

Minor issues with limited security impact. This includes missing security headers, verbose error messages exposing internal details, clickjacking on non-sensitive pages, or outdated software versions with no known exploit path.

Bonus Awards

Tiquo reserves the right to award bonuses above the stated ranges for exceptional reports. Factors that may qualify a submission for a bonus include particularly well-written reports with clear reproduction steps, vulnerabilities with widespread impact across multiple systems, creative exploitation chains that reveal deeper architectural issues, or researchers who work closely with our team during remediation. Bonus amounts are determined on a case-by-case basis.

Submission Guidelines

To help us investigate quickly, please include the following in your report:

  • 1
    A clear description of the vulnerability
  • 2
    Step-by-step reproduction instructions
  • 3
    The affected URL, endpoint, or application screen
  • 4
    Your testing environment (browser, OS, device)
  • 5
    Screenshots or proof-of-concept code where possible
  • 6
    Your assessment of the potential impact

Please submit one vulnerability per report. If you've found multiple issues, send a separate report for each.

Rules of Engagement

  • 1
    Do not access, modify, or delete data belonging to other users.
  • 2
    Do not run automated scanning tools against production systems without prior written approval from Tiquo.
  • 3
    어떤 취약점, 보고서, proof of concept 또는 관련 세부 사항도 언제든 공개하지 마세요.
  • 4
    보고서를 생성하거나 작성하는 데 AI 도구 또는 대규모 언어 모델을 사용하지 마세요. 저희는 직접 수행한 실무 테스트에 기반한 독창적인 연구를 원합니다. AI가 생성한 것으로 보이거나, 추측성이거나, 실제로 수동 검증된 취약점에 기반하지 않은 제출물은 검토 없이 거부되며 프로그램에서 제외될 수 있습니다.
  • 5
    Act in good faith at all times.

Safe Harbour

선의로 행동하고 위 규칙을 따르는 보안 연구자는 Tiquo로부터 법적 조치를 받지 않습니다. 이 정책에 따라 수행되는 책임 있는 보안 연구는 승인된 활동으로 간주합니다. 이 프로그램을 준수하는 연구자에 대해 민사 또는 형사 조치를 취하지 않습니다. 이 프로그램은 Tiquo의 재량에 따라 제공됩니다. 당사는 모든 제출물에 대해 자격, 심각도 및 보상 금액을 결정하고, 언제든지 프로그램을 수정, 중단 또는 종료할 권리를 보유합니다. Tiquo의 모든 결정은 최종적이며, 참여가 보상에 대한 계약상 권리를 생성하지 않습니다.

Contact

Submit your reports to:

security@tiquo.co

모든 보고서는 제출 후 24시간 이내에 내부 검토됩니다. 공식 답변은 더 오래 걸릴 수 있습니다. 분류는 문제의 복잡성과 재현 및 평가에 필요한 시간에 따라 달라지기 때문입니다. 보고서 상태를 확인하기 위한 후속 메시지는 보내지 마세요. 재촉 이메일은 모두의 검토를 늦춥니다. 업데이트가 있는 즉시 연락드리며, 최초 평가는 영업일 기준 10일 이내에 받을 수 있습니다.

쿠키를 사용합니다

저희 사이트에서 사용자 경험을 개선하기 위해 쿠키를 사용합니다. 계속 탐색하면 쿠키 사용에 동의하는 것입니다.

자세히 알아보기