Security & bug bounty

Help us keep payments secure.

We handle money and sensitive data for thousands of businesses. If you find a vulnerability, we reward you – fairly and quickly.

180k €+
Rewards paid out so far
< 2 days
first response to reports
340+
Vulnerabilities fixed
120+
Researchers worldwide

Rewards by severity

The amount depends on impact and exploitability (CVSS). The final classification is made by our security team.

CRITICAL

RCE, access to payment data, large-scale authentication bypass.

CVSS 9.0–10.0
HIGH

Account takeover, significant data leaks, IDOR on sensitive resources.

CVSS 7.0–8.9
MEDIUM

Stored XSS, CSRF with impact, privilege escalation with limitations.

CVSS 4.0–6.9
LOW

Minor information leaks, configuration weaknesses with little impact.

CVSS 0.1–3.9
Scope

Where you may look

All production LEVIAPAY systems are part of the programme. The following is explicitly out of scope:

  • Social engineering, phishing against staff or customers
  • DoS/DDoS and volumetric load testing
  • Pure best-practice notes with no demonstrable impact (missing headers, for instance)
  • Vulnerabilities in third-party services with no connection to LEVIAPAY
  • Automated scanner reports without a validated PoC
Active targets
app.leviapay.com
Merchant dashboard & web app
Web
api.leviapay.com
Public & internal APIs
API
wiki.leviapay.com
Help centre & support
Web
LEVIAPAY iOS & Android
Current app versions
Mobile
*.leviapay.com
Further production subdomains
Infra

How it works

1

Report

Submit your report through the form or by PGP email.

2

Triage

We confirm receipt within 2 working days and review the finding.

3

Fix

We fix the vulnerability and keep you posted on the progress.

4

Reward

After verification we pay the reward and, if you like, add you to the hall of fame.

Ground rules

Safe harbour

Anyone who follows these rules and researches in good faith has nothing to fear from us legally. We consider such research authorised and will work with you on a swift fix.

Report now

Hall of fame

Thank you to the researchers who make LEVIAPAY safer.

NV
@n0va_sec
9 findings
BW
@bytewitch
7 findings
KR
@kr1ll
6 findings
M4
@m4ple
5 findings
OX
@oxide
4 findings
SC
@sn0wcap
4 findings
V3
@v3ctor
3 findings
LH
@lina.h
3 findings

Found a vulnerability?

Submit your report – encrypted via PGP if you prefer. We reply within 2 working days.