We handle money and sensitive data for thousands of businesses. If you find a vulnerability, we reward you – fairly and quickly.
The amount depends on impact and exploitability (CVSS). The final classification is made by our security team.
RCE, access to payment data, large-scale authentication bypass.
Account takeover, significant data leaks, IDOR on sensitive resources.
Stored XSS, CSRF with impact, privilege escalation with limitations.
Minor information leaks, configuration weaknesses with little impact.
All production LEVIAPAY systems are part of the programme. The following is explicitly out of scope:
Submit your report through the form or by PGP email.
We confirm receipt within 2 working days and review the finding.
We fix the vulnerability and keep you posted on the progress.
After verification we pay the reward and, if you like, add you to the hall of fame.
Anyone who follows these rules and researches in good faith has nothing to fear from us legally. We consider such research authorised and will work with you on a swift fix.
Report nowThank you to the researchers who make LEVIAPAY safer.
Submit your report – encrypted via PGP if you prefer. We reply within 2 working days.