Rationale
Billease strives to maintain the overall security of its systems and acknowledges that a unilateral approach to this objective is not optimal. Therefore, we're opening this bug bounty program to security researchers to try and find vulnerabilities in our systems for a corresponding bounty.
Program Scope
Here's a list of what we consider fair game for researchers to test:
- https://billease.ph
- Billease Android App
- Billease iOS App
- Other Billease assets
As of now, we're only open for public testing (unauthenticated) of our services.
Security Researcher Requirements
For submissions to be recognized, the security researcher should:
- provide Billease with a reasonable amount of time to resolve reported verified security vulnerabilities;
- attempt to preserve the confidentiality of any data that might have been compromised;
- avoid leaking vulnerability details to third-parties for external payouts not from Billease or otherwise;
- not defraud Billease, its systems and employees, in researching a vulnerability;
- not use any discovered vulnerabilities to harass, threaten, or blackmail Billease.
Should you plan to engage in conduct that is beyond the scope of our policies, please reach out to [email protected] so that we might assess its qualifications.
Our Pledge
In line with our commitment to deliver to better serve the unbanked Filipinos with accessible credit and to show our gratitude to security researchers who will be testing our systems systems and following our guidelines we will:
- address and resolve reported and verified security vulnerabilities;
- refrain from penalizing security researchers from applicable system exploitation laws; and
- award commensurate bounty for verified vulnerabilities.
Excluded Vulnerabilities
We have a number of vulnerabilities that are not eligible in for reporting in our Bug Bounty Program:
- Theoretical vulnerabilities without actual proof of concept
- Clickjacking
- Known issues publicized by Billease
- Unilateral expiring password token availability to third parties
- Deprecated Mobile App and/or Browser Platforms
- Jailbreak or root device exploits
- Tab-nabbing
- Web or Mobile App performance issues
- Issues related to unsafe SSL/TLS cipher suites or protocol version
- Content spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.
- Social engineering exploits
- Low-impact CSRF issues
- CSP Headers, X-Frame-Options, Content sniffing, HPKP, etc
- Assets not owned by Billease
- Missing security headers that do not lead to direct exploitation
- Self-XSS
- Service issues that have no security impact
- Phishing
- Vulnerabilities that require physical access to a user’s device
- DDoS Attacks (intentional or not)
- Missing best practices without a working Proof of Concept
- Man-in-the-middle (MITM) attacks
Submission Protocol
Found a legitimate security vulnerability? Attach the following to your message:
- vulnerability details;
- Proof of Concept or reproduction steps; and
- CVSS details and scores;
and send it to our Security and Privacy officer at [email protected].
Reward Schedule
As soon as Billease receives your submission, we will verify its authenticity and triage it accordingly. A reply will follow to render Billease's classification of the vulnerability along with the appropriate bounty amount.
Security
Billease Bug Bounty Program
Last updated at 2022 April 4.