Chuyển đến nội dung chính

Tiquo Bug Bounty Program

At Tiquo, we take the security of our platform seriously. We value the work of security researchers and welcome responsible disclosure of vulnerabilities. If you discover a security issue, we'd like to hear from you.

How It Works

1

You discover a potential security vulnerability in a Tiquo product.

2

You submit a detailed report to our security team.

3

Chúng tôi xem xét báo cáo của bạn nội bộ trong vòng 24 giờ. Phản hồi chính thức của chúng tôi có thể được gửi sau.

4

Our team investigates, reproduces, and classifies the severity of the issue.

5

We notify you of our classification and the reward amount.

6

Payment is issued within 30 days of classification.

All severity classifications and reward amounts are determined by Tiquo after submission. We assess every report individually based on the real-world impact, exploitability, and scope of the vulnerability.

What's in Scope

Our bug bounty program covers the following:

  • tiquo.co
  • Tiquo API endpoints
  • Tiquo iOS and Android mobile applications
  • tiquo.app webapp / dashboard
  • Authentication and authorization flows
  • Payment and data handling processes
  • Tiquo hardware

What's Out of Scope

The following are not eligible for rewards:

  • Third-party services or integrations not owned by Tiquo
  • Social engineering or phishing attacks against Tiquo employees
  • Denial of service (DoS/DDoS) attacks
  • Spam or rate-limiting issues with no direct security impact
  • Isolated projects which have no sensitive data or customer information
  • Vulnerabilities requiring outdated browsers or platforms
  • Issues that have already been reported or are already known to us
  • Báo cáo do AI tạo, tự động hoặc mang tính suy đoán, không dựa trên proof of concept hoạt động đã được xác minh thủ công.

Reward Tiers

We classify all submissions into four severity levels. The final reward is determined by Tiquo based on the quality of the report, the severity of the vulnerability, and the potential impact to our users.

Critical
£1,000 to £10,000

Vulnerabilities that could cause severe, company-wide damage. This includes remote code execution, full database access, authentication bypass granting access to all user accounts, payment system compromise, or mass exfiltration of personal or financial data.

High
£150 to £1,000

Significant vulnerabilities that affect individual users or expose sensitive data. This includes privilege escalation, stored cross-site scripting in sensitive contexts, insecure direct object references exposing other users' data, or broken access controls on API endpoints.

Medium
£50 to £150

Vulnerabilities that require specific conditions or user interaction to exploit. This includes reflected cross-site scripting, cross-site request forgery on sensitive actions, information disclosure of internal system data, or misconfigured CORS policies.

Low
£10 to £50

Minor issues with limited security impact. This includes missing security headers, verbose error messages exposing internal details, clickjacking on non-sensitive pages, or outdated software versions with no known exploit path.

Bonus Awards

Tiquo reserves the right to award bonuses above the stated ranges for exceptional reports. Factors that may qualify a submission for a bonus include particularly well-written reports with clear reproduction steps, vulnerabilities with widespread impact across multiple systems, creative exploitation chains that reveal deeper architectural issues, or researchers who work closely with our team during remediation. Bonus amounts are determined on a case-by-case basis.

Submission Guidelines

To help us investigate quickly, please include the following in your report:

  • 1
    A clear description of the vulnerability
  • 2
    Step-by-step reproduction instructions
  • 3
    The affected URL, endpoint, or application screen
  • 4
    Your testing environment (browser, OS, device)
  • 5
    Screenshots or proof-of-concept code where possible
  • 6
    Your assessment of the potential impact

Please submit one vulnerability per report. If you've found multiple issues, send a separate report for each.

Rules of Engagement

  • 1
    Do not access, modify, or delete data belonging to other users.
  • 2
    Do not run automated scanning tools against production systems without prior written approval from Tiquo.
  • 3
    Không công khai bất kỳ lỗ hổng, báo cáo, proof of concept hoặc chi tiết liên quan nào vào bất kỳ thời điểm nào.
  • 4
    Không sử dụng công cụ AI hoặc mô hình ngôn ngữ lớn để tạo hoặc viết báo cáo của bạn. Chúng tôi muốn nghiên cứu gốc dựa trên thử nghiệm thực tế do chính bạn thực hiện. Các submission có vẻ do AI tạo, mang tính suy đoán hoặc không dựa trên một lỗ hổng thật đã được xác minh thủ công sẽ bị từ chối mà không được xem xét và có thể dẫn đến việc bị loại khỏi chương trình.
  • 5
    Act in good faith at all times.

Safe Harbour

Các nhà nghiên cứu bảo mật hành động thiện chí và tuân thủ các quy tắc trên sẽ không phải đối mặt với hành động pháp lý từ Tiquo. Chúng tôi coi nghiên cứu bảo mật có trách nhiệm được thực hiện theo chính sách này là hoạt động được cho phép. Chúng tôi sẽ không theo đuổi hành động dân sự hoặc hình sự đối với các nhà nghiên cứu tuân thủ chương trình này. Chương trình này được cung cấp theo quyết định của Tiquo. Chúng tôi bảo lưu quyền xác định tính đủ điều kiện, mức độ nghiêm trọng và phần thưởng cho bất kỳ submission nào, cũng như sửa đổi, tạm dừng hoặc kết thúc chương trình bất cứ lúc nào. Mọi quyết định của Tiquo là cuối cùng, và việc tham gia không tạo ra bất kỳ quyền theo hợp đồng nào đối với phần thưởng.

Contact

Submit your reports to:

security@tiquo.co

Mỗi báo cáo được xem xét nội bộ trong vòng 24 giờ sau khi gửi. Xin lưu ý rằng phản hồi chính thức của chúng tôi có thể mất nhiều thời gian hơn, vì việc phân loại phụ thuộc vào độ phức tạp của vấn đề và thời gian cần thiết để tái tạo và đánh giá. Vui lòng không gửi tin nhắn theo dõi để hỏi tình trạng báo cáo của bạn. Email thúc giục làm chậm quá trình xem xét cho mọi người. Chúng tôi sẽ liên hệ với bạn ngay khi có cập nhật, và bạn có thể mong đợi đánh giá ban đầu trong vòng 10 ngày làm việc.

Chúng tôi sử dụng cookie

Chúng tôi sử dụng cookie để cải thiện trải nghiệm của bạn trên trang web. Bằng cách tiếp tục duyệt, bạn đồng ý với việc sử dụng cookie của chúng tôi.

Tìm hiểu thêm