Vulnerability Disclosure &
Bug Bounty Program
At DepiPay, security is fundamental to everything we do. We welcome responsible security research and encourage independent researchers to report vulnerabilities in accordance with this policy.
Scope
The following domains are in scope for testing:
*.depipay.com/*
In-scope assets include publicly accessible production web applications and APIs owned and operated by DepiPay hosted under these domains.
Out of scope:
- DepiPay mobile applications
- Third-party systems or services not owned by DepiPay
- Official plugins where the issue is specific to the shopping cart platform
- VPN-restricted, staging, internal administrative systems and infrastructure
If you are unsure whether a system is in scope, contact us before conducting testing.
Reward Structure
Rewards are determined based on severity, business impact, exploitability, and report quality. Amounts are guideline ranges and do not guarantee a payout.
| Severity | Examples | Reward |
|---|---|---|
| Critical | SQL injection, RCE, remote file inclusion, privilege escalation, unauthorized wallet access | $1,000+ |
| High | Customer data disclosure, authentication bypass, significant authorization weaknesses | $500+ |
| Medium | Persistent XSS, CSRF on sensitive forms | $250+ |
| Low | Provisioning errors, information disclosure, limited-impact weaknesses | $100+ |
| Very Low | Non-persistent XSS, mixed content issues, tab-nabbing | $50+ |
Severity is determined using CVSS v3.1 and business impact assessment. DepiPay reserves the right to determine final classification and reward amounts.
Rewards are paid within 10 days following validation to the researcher's USDT or USDC wallet. Payment may require identity verification.
Responsible Research Guidelines
To be eligible for a reward, you must:
- Be the first to report the vulnerability (duplicates go to first valid report)
- Provide sufficient technical detail for reproduction
- Avoid accessing, modifying, or exfiltrating real user data
- Avoid service disruption or degradation
- Comply with all applicable laws
- Follow the disclosure requirements below
Strictly prohibited:
- Denial of Service (DoS/DDoS)
- Brute force attacks
- Spam or mail abuse techniques
- Social engineering or phishing
- Attacks targeting DepiPay employees or users
- Testing that compromises data integrity or system availability
- Credential stuffing and automated account enumeration
Automated testing tools are permitted provided they do not cause service disruption or excessive traffic.
Disclosure Policy
DepiPay follows a coordinated disclosure approach. Researchers must:
- Maintain confidentiality of findings
- Not publicly disclose vulnerabilities without written authorization
- Wait at least 30 business days after reporting before public disclosure unless otherwise agreed
Failure to follow disclosure requirements may result in disqualification from the program.
Non-Qualifying Submissions
The following are not eligible for rewards:
- Automated scan output without clear validation or impact demonstration
- Publicly known vulnerabilities
- Issues already known to DepiPay
- Findings without DepiPay-specific testing
- Issues requiring prior access to a victim account or device
- Path or version disclosure
- Spoofed email reports
- HTTP security header issues without exploitable proof of concept
- SSL/TLS configuration concerns without exploitable proof of concept
- Issues not reproducible in current versions of major browsers
- Vulnerabilities dependent on browser extensions
Safe Harbor
If you act in good faith and comply with this policy, we will not pursue civil or criminal action, nor report you to law enforcement. We will consider your testing authorized and work with you to understand and resolve the issue.
Testing within scope and compliance with this policy is authorized. Testing is permitted only on accounts you own or have explicit permission to test.
How to Report
Submit reports to: security@depipay.com
Include:
- Detailed reproduction steps
- Affected URLs
- Proof of concept
- Description of impact
- Environment details (browser, OS, etc.)