We pay for stolen funds
and taken accounts.

Everything else we will read, maybe fix, and close without a reward. The bar is deliberately high.

What we pay for

A report qualifies if you can demonstrate one of these against a production host in scope.

  1. Moving, crediting, or withdrawing funds you are not entitled to, including balance manipulation and race conditions in wallet or order operations.
  2. Taking over another user's, partner's, or admin's account.
  3. Bypassing authentication or authorization to read or change another account's data (KYC documents, personal data, transactions, API keys).
  4. Remote code execution, SQL injection, or SSRF that reaches internal services.
  5. Leaked credentials or secrets that grant access to production systems, with proof that they work.
  6. Stored XSS with a working chain to session or account compromise.

Severity is ours to assign. We look at what an attacker gains, not at a CVSS score produced by a tool.

What we do not accept

We do not pay for low or informational findings and we do not negotiate on this. Closed on sight, whatever severity you label them.

Full exclusion list 18 items
  • Missing or weak security headers, cookie flags, CSP, HSTS, and CORS misconfiguration with no working exploit.
  • TLS and certificate configuration, weak ciphers, protocol support.
  • Missing SPF, DKIM, or DMARC records, and email spoofing without impact.
  • Rate limiting, brute force, and missing captcha, unless you compromised an account with it.
  • Self-XSS, XSS that needs the victim to paste something into a console, and content or text injection without script execution.
  • Clickjacking, tabnabbing, missing rel="noopener", and open redirects with no credential or token theft.
  • CSRF on endpoints that change nothing sensitive, including logout CSRF.
  • User or email enumeration, and timing or response differences in login, registration, or password reset.
  • Version disclosure, banner grabbing, stack traces, verbose errors, exposed source maps, directory listings, and publicly readable static assets.
  • Denial of service, resource exhaustion, and ReDoS.
  • Dependency reports based on a version number with no working exploit path in our code.
  • Vulnerabilities in third parties we integrate with (SumSub, TradeVest, BlackManta, AWS, Cloudflare). Report those to them.
  • Anything that needs a rooted device, a compromised browser, physical access, or interception of the victim's own traffic.
  • Social engineering, phishing, and attacks against our staff or offices.
  • Scanner output submitted without your own analysis and a working proof of concept.
  • Best practice advice with no attack behind it.
  • Findings in bundled third-party libraries or SDKs (Google Trusted Web Activity / androidbrowserhelper, WebView, analytics SDKs, and similar) with no exploit of code we wrote. Report those upstream.
  • Mobile OS or platform CVEs that require an outdated, unsupported, rooted, or jailbroken device to reproduce, or that stop working on a current OS release.

We also do not issue certificates, letters of recognition, or hall of fame entries for findings on this list. Please do not ask.

Scope

Production only. Anything not listed is out of scope.

Host What it is
app.lympid.io Lympid app
Partner tenants on *.lympid.io Partner-branded whitelabel apps
partner.lympid.io Partner portal
api.lympid.io, partner-api.lympid.io Partner API

Out of scope includes staging and test hosts (staging.lympid.io, *-test.lympid.io), our marketing site, our Android and iOS apps, and the third-party services named above. A finding on an out-of-scope host, app, or package is not eligible even if the same bug would qualify on a production host.

Rules for testing

What your report must contain

Email one issue per report to client.journey@lympid.io, with the affected host in the subject line.

We acknowledge reports within five business days. If yours qualifies we say so and keep you updated until the fix ships. If it does not, we close it with a one-line reason and will not debate the classification.

Rewards

Every qualifying report is priced on its own. The amount comes from the impact you demonstrated and the quality of the write-up. There is no published table and no minimum. A clear report on a fund-draining bug pays well; a vague report on the same bug pays less, because we have to redo the work you skipped.

Only the first person to report an issue is paid. Duplicates, issues we already know about, and issues already fixed in an unreleased branch earn nothing.

Safe harbor

Stay inside these rules and we treat your testing as authorized. We will not pursue legal action against you and will not ask anyone else to. Step outside them, by touching real user data, breaking something deliberately, or trying to extort us, and none of this applies.