DepiPay Security Program

Vulnerability Disclosure &
Bug Bounty Program

At DepiPay, security is fundamental to everything we do. We welcome responsible security research and encourage independent researchers to report vulnerabilities in accordance with this policy.

Strong security controls across our infrastructure
Prompt response to valid vulnerability reports
Collaborative work with security researchers
Safe harbor for responsible research within this policy

Scope

The following domains are in scope for testing:

  • *.depipay.com/*

In-scope assets include publicly accessible production web applications and APIs owned and operated by DepiPay hosted under these domains.

Out of scope:

  • DepiPay mobile applications
  • Third-party systems or services not owned by DepiPay
  • Official plugins where the issue is specific to the shopping cart platform
  • VPN-restricted, staging, internal administrative systems and infrastructure

If you are unsure whether a system is in scope, contact us before conducting testing.

Reward Structure

Rewards are determined based on severity, business impact, exploitability, and report quality. Amounts are guideline ranges and do not guarantee a payout.

SeverityExamplesReward
CriticalSQL injection, RCE, remote file inclusion, privilege escalation, unauthorized wallet access$1,000+
HighCustomer data disclosure, authentication bypass, significant authorization weaknesses$500+
MediumPersistent XSS, CSRF on sensitive forms$250+
LowProvisioning errors, information disclosure, limited-impact weaknesses$100+
Very LowNon-persistent XSS, mixed content issues, tab-nabbing$50+

Severity is determined using CVSS v3.1 and business impact assessment. DepiPay reserves the right to determine final classification and reward amounts.

Rewards are paid within 10 days following validation to the researcher's USDT or USDC wallet. Payment may require identity verification.

Responsible Research Guidelines

To be eligible for a reward, you must:

  • Be the first to report the vulnerability (duplicates go to first valid report)
  • Provide sufficient technical detail for reproduction
  • Avoid accessing, modifying, or exfiltrating real user data
  • Avoid service disruption or degradation
  • Comply with all applicable laws
  • Follow the disclosure requirements below

Strictly prohibited:

  • Denial of Service (DoS/DDoS)
  • Brute force attacks
  • Spam or mail abuse techniques
  • Social engineering or phishing
  • Attacks targeting DepiPay employees or users
  • Testing that compromises data integrity or system availability
  • Credential stuffing and automated account enumeration

Automated testing tools are permitted provided they do not cause service disruption or excessive traffic.

Disclosure Policy

DepiPay follows a coordinated disclosure approach. Researchers must:

  • Maintain confidentiality of findings
  • Not publicly disclose vulnerabilities without written authorization
  • Wait at least 30 business days after reporting before public disclosure unless otherwise agreed

Failure to follow disclosure requirements may result in disqualification from the program.

Non-Qualifying Submissions

The following are not eligible for rewards:

  • Automated scan output without clear validation or impact demonstration
  • Publicly known vulnerabilities
  • Issues already known to DepiPay
  • Findings without DepiPay-specific testing
  • Issues requiring prior access to a victim account or device
  • Path or version disclosure
  • Spoofed email reports
  • HTTP security header issues without exploitable proof of concept
  • SSL/TLS configuration concerns without exploitable proof of concept
  • Issues not reproducible in current versions of major browsers
  • Vulnerabilities dependent on browser extensions

Safe Harbor

If you act in good faith and comply with this policy, we will not pursue civil or criminal action, nor report you to law enforcement. We will consider your testing authorized and work with you to understand and resolve the issue.

Testing within scope and compliance with this policy is authorized. Testing is permitted only on accounts you own or have explicit permission to test.

How to Report

Submit reports to: security@depipay.com

Include:

  • Detailed reproduction steps
  • Affected URLs
  • Proof of concept
  • Description of impact
  • Environment details (browser, OS, etc.)
Our security team will review your report and respond within 10 working days. DepiPay operates this program with a limited reward budget and reserves the right to modify reward ranges, pause bounty awards, or suspend the program at any time.