Report a Vulnerability
Aspora's Bug Bounty Program — how to responsibly disclose security vulnerabilities in our products, and how we review, fix, and reward valid reports.
1. Introduction
Aspora builds borderless financial products for the global diaspora — money transfers, NRI banking, digital gold, and bill payments — used by more than a million people to move money across borders. Because we handle people's money and personal data, the security of our systems is a first-order responsibility.
This Bug Bounty Program invites independent security researchers to responsibly find and report vulnerabilities in Aspora's systems. In return, we commit to reviewing every valid report, fixing confirmed issues quickly, recognising the researchers who help us, and rewarding qualifying findings. This document explains what is in scope, how to report, how we assess severity, what we pay, and the terms that govern participation.
We would rather hear about a vulnerability from you than from an attacker. Thank you for helping us keep our users' money and data safe.
2. Program at a Glance
| Item | Detail |
|---|---|
| Who can participate | Any independent security researcher who meets the eligibility rules in Section 11 |
| How to report | Email security@aspora.com (PGP available on request), using the template in Section 6 |
| What we reward | Previously unknown, in-scope, reproducible security vulnerabilities |
| Reward range | Recognition up to USD 1,000, based on severity (Section 5) |
| First response | Within 3 business days |
| Disclosure model | Coordinated disclosure — see Section 8 |
| Safe harbour | Good-faith research authorised under Section 9 |
3. Scope
3.1 In scope
The following Aspora assets are in scope for this program:
- Mobile applications — the official Aspora apps for iOS (Apple App Store) and Android (Google Play), including the current production release and the most recent prior release.
- Public / backend APIs — the public-facing and mobile-backing APIs that power the Aspora apps (for example, hosts under
api.aspora.comand related production API endpoints). - Infrastructure — internet-facing infrastructure operated by Aspora, including DNS configuration, email authentication (SPF, DKIM, DMARC), TLS/certificate configuration, and cloud assets under Aspora-owned domains.
If you are unsure whether a specific asset, subdomain, or endpoint is in scope, email security@aspora.com and ask before testing. We would rather answer a question than have you test something you shouldn't.
3.2 Out of scope
Testing against the following is not authorised and is not eligible for a reward:
- Any system, service, or data that does not belong to Aspora, including third-party providers such as banking partners, payment processors, exchange partners (e.g. Lulu International Exchange), KYC/identity vendors, analytics, email, or cloud vendors. Report those to the relevant vendor.
- Physical attacks against Aspora offices, staff, or data centres.
- Social engineering, phishing, or vishing of Aspora employees, contractors, users, or partners.
- Denial-of-service (DoS/DDoS), volumetric, brute-force, or any load/stress testing.
- Automated scanning that generates high-volume traffic without prior written approval.
- Attacks requiring a rooted/jailbroken device, a compromised OS, physical access to an unlocked device, or a man-in-the-middle position the user themselves must enable.
- Reports from automated tools or scanners without a demonstrated, exploitable impact.
3.3 Excluded issue types
The following are generally not eligible unless you can chain them into a concrete, demonstrable security impact:
- Missing security headers (CSP, HSTS, X-Frame-Options, etc.) with no proven exploit.
- Missing best-practice cookie flags with no demonstrated impact.
- Clickjacking on pages with no sensitive state-changing action.
- Self-XSS, or issues that require a victim to paste attacker-supplied code into their own console.
- Email/SMS bombing, rate-limiting on non-sensitive endpoints, or lack of CAPTCHA.
- Descriptive error messages, stack traces, or banner/version disclosure without sensitive data.
- Vulnerabilities in third-party libraries without a working proof of concept against Aspora.
- Reports based solely on outputs from automated tools, CVSS calculators, or "theoretical" risk.
- Presence of a mobile app on a rooted/jailbroken device, or lack of code obfuscation, absent a concrete exploit.
- Absence of SSL/certificate pinning on its own (see Known Issues, Section 3.4).
- Presence of client-side Firebase configuration or API keys in the mobile app binary. These values are designed to be shipped in the client and are not secrets; their mere presence is not a vulnerability (see Known Issues, Section 3.4).
- Publicly known vulnerabilities disclosed within the last 30 days for which a patch is not yet reasonably available.
3.4 Known issues (accepted / already tracked)
The items below are already known to the Aspora Security Team. Reporting their mere existence will not earn a reward. However, if you can chain one of them into a concrete, demonstrated security impact, that working exploit is eligible — report it and describe the full attack.
- No SSL/certificate pinning in the Android app. We are aware the Android app does not currently pin certificates. Simply pointing this out is out of scope. A working proof of concept that uses this to intercept, read, or modify real user traffic under realistic conditions (i.e. not requiring a device the attacker already fully controls) is in scope and will be assessed on its demonstrated impact.
- Firebase used for configuration, not user data. Aspora uses Firebase (e.g. Remote Config) for app configuration, not as a database for personal or financial data. Reporting that Firebase config/keys are visible in the app, or that a Firebase project exists, is out of scope. In scope: any misconfigured Firebase security rule that permits unauthorised read or write, any path that exposes personal, KYC, or financial data, or any way to tamper with configuration to affect users — demonstrate it with a proof of concept.
4. How We Rank Severity
We assess each valid report on the realistic, demonstrable impact to Aspora's users, funds, and data — not on theoretical worst cases. We use CVSS v3.1 as a starting reference and then adjust for real-world exploitability and the sensitivity of the affected data or funds. Aspora is the final arbiter of severity.
| Severity | What it typically looks like at Aspora |
|---|---|
| Critical | Direct theft or unauthorised movement of user funds; remote code execution on production servers; full authentication bypass; large-scale exposure of KYC documents, bank details, or full PII of many users. |
| High | Account takeover of an arbitrary user; access to another user's transactions, balances, or personal data (IDOR on sensitive objects); significant authorisation flaws; SQL injection exposing sensitive data. |
| Medium | Limited data exposure; stored XSS affecting other users; CSRF on a sensitive action; authentication weaknesses that require unusual preconditions; business-logic flaws with moderate impact. |
| Low | Issues with minimal security impact; reflected XSS requiring significant user interaction; minor information disclosure; misconfigurations with limited exploitability. |
| Informational | Best-practice suggestions and hardening opportunities with no directly demonstrable security impact. |
5. Rewards
Aspora's program is early-stage and rewards are modest but real. All amounts are in US dollars and represent the maximum payable for a single report at that severity. The actual amount within each band is decided by Aspora based on impact, report quality, and reproducibility.
| Severity | Reward (up to) |
|---|---|
| Critical | $1,000 |
| High | $500 |
| Medium | $150 |
| Low | $50 |
| Informational | Public recognition / swag (no cash) |
5.1 How rewards are decided
- One reward per unique root cause. If a single underlying bug produces several symptoms, it is treated as one report.
- First valid reporter wins. For duplicate reports, only the first researcher to submit a reproducible report is eligible. Later duplicates receive our thanks but no reward.
- Report quality matters. Clear, well-documented reports with a working proof of concept are rewarded toward the top of the band; vague reports we cannot reproduce are rewarded toward the bottom, or not at all.
- Chained bugs are rewarded at the severity of the combined impact you demonstrate.
- Rewards are discretionary and decided in good faith by the Aspora Security Team.
5.2 Recognition
With your permission, we will list your name or handle in an Aspora Security Hall of Fame / acknowledgements page. You may also choose to remain anonymous.
5.3 Payment and taxes
Rewards are paid after the vulnerability is confirmed and remediated (or a remediation plan is agreed). We will coordinate a payment method with you. You are responsible for any taxes applicable in your jurisdiction, and you must be able to receive payment lawfully (see eligibility in Section 11).
6. How to Report
Send your report to security@aspora.com. A PGP key is available on request for encrypting sensitive details. Please include:
- Summary — a one-line description of the issue and its impact.
- Affected asset — the exact app version, API endpoint, host, or component.
- Vulnerability type — e.g. IDOR, authentication bypass, injection.
- Steps to reproduce — a clear, numbered, step-by-step walkthrough.
- Proof of concept — request/response samples, screenshots, or a short screen recording. Please redact any real user data.
- Impact — what an attacker could realistically achieve.
- Suggested remediation — optional, but appreciated.
- Your details — how you'd like to be credited, and a contact address for reward coordination.
Please submit one vulnerability per report unless you need to chain several to demonstrate impact.
7. Response Targets
We aim to work at the pace the severity deserves:
| Stage | Target |
|---|---|
| Acknowledgement of your report | Within 3 business days |
| Triage and severity decision | Within 10 business days |
| Status updates while we investigate | At least every 10 business days |
| Remediation of confirmed issues | Prioritised by severity; Critical/High treated as urgent |
| Reward decision | After triage confirms validity and uniqueness |
Business days are counted in the UK (GMT/BST). Complex issues may take longer — we'll keep you informed.
8. Coordinated Disclosure Policy
- Please give us a reasonable opportunity to remediate before any public disclosure — a minimum of 90 days from your initial report, or until a fix is deployed, whichever comes first.
- Coordinate the timing and content of any public disclosure with us in advance at security@aspora.com. We're happy to co-author or review a write-up.
- Do not disclose the vulnerability, or any user data you encountered, to any third party at any time.
- If an issue poses an active, serious risk to users, we may ask you to hold disclosure longer, and we'll explain why.
We will not take legal action against researchers who follow this policy in good faith (see Safe Harbour, Section 9).
9. Safe Harbour
Aspora considers security research and vulnerability disclosure conducted in accordance with this policy to be authorised, good-faith conduct. If you make a good-faith effort to comply with this policy during your research, we will:
- Regard your activity as authorised under applicable computer-misuse and anti-hacking laws, and not pursue or support legal action against you for accidental, good-faith violations of this policy;
- Work with you to understand and resolve the issue quickly; and
- Recognise your contribution as described above.
This safe harbour applies only to legal claims under Aspora's control. It does not authorise you to act unlawfully, to affect users or third parties, or to bind any third party (including our banking, payment, and exchange partners). If in doubt about whether an action is authorised, stop and ask us first at security@aspora.com.
If legal action is initiated by a third party against you for activities conducted under this policy, we will take reasonable steps to make it known that your actions were authorised.
10. Rules of Engagement
By participating you agree to:
- Only test assets that are in scope (Section 3.1). Never touch out-of-scope systems or third-party services.
- Respect privacy. Do not access, modify, download, retain, or destroy any data that is not your own. Use only test accounts you create for this purpose. If you inadvertently encounter another person's data (PII, KYC documents, transaction data, credentials), stop immediately, do not save or share it, and report it to us.
- Do no harm. Do not degrade, disrupt, or damage Aspora systems or the experience of our users. No DoS, no data destruction, no automated high-volume testing.
- Use non-destructive proofs of concept. Demonstrate impact with the minimum action necessary — for example, read a single non-sensitive record rather than exfiltrating a database.
- Do not use real user funds or attempt actual fraudulent transactions. Simulate with your own test accounts.
- Keep it confidential. Do not disclose findings publicly until coordinated disclosure is agreed (Section 8).
- Comply with all applicable laws in your jurisdiction and in the jurisdictions where Aspora operates.
Violating these rules removes safe-harbour protection and disqualifies you from rewards.
11. Eligibility
To receive a reward you must:
- Be at least 18 years old, or have the consent of a parent/legal guardian.
- Not be a current or former (within the last 12 months) Aspora employee, contractor, or vendor, nor an immediate family member or household member of one.
- Not be a resident of, or located in, any country subject to comprehensive sanctions or trade restrictions administered by the US (OFAC), UK, EU, or UN, and not be an individual or entity on any applicable sanctions or denied-parties list. Aspora cannot pay rewards where doing so would violate applicable law.
- Be the first researcher to report a given unique vulnerability.
- Comply fully with this policy, including the rules of engagement.
Aspora reserves the right to determine eligibility and to withhold rewards where these conditions are not met.
12. Terms and Conditions
- Program changes. Aspora may modify, suspend, or terminate this program, and may change scope, severity criteria, and reward amounts, at any time and without notice. The version of the policy in effect at the time of your report governs that report.
- Discretion. All reward decisions, severity assessments, duplicate determinations, and eligibility decisions are made at Aspora's sole discretion, exercised reasonably and in good faith. Aspora is the final arbiter.
- No relationship. Participation does not create any employment, agency, partnership, or joint-venture relationship between you and Aspora, and does not obligate Aspora to engage you for any paid work.
- Intellectual property and use of reports. You grant Aspora a perpetual, worldwide, royalty-free licence to use, reproduce, and act on the contents of your report for the purposes of assessing and remediating the issue and improving our security. You agree not to assert any claim against Aspora arising from our use of information you submit. You confirm your submission is your original work and does not infringe the rights of any third party.
- No guarantee of reward. Submitting a report does not guarantee a reward. Rewards are granted only for qualifying reports as described in this policy.
- Confidentiality. Information you learn about Aspora's systems through this program is confidential and may be used only for the purpose of preparing and submitting a report.
- Data protection. Any personal data you provide to us (such as your name and contact/payment details) will be processed in line with Aspora's privacy practices, solely to administer this program, communicate with you, and pay rewards.
- Governing law. This program is operated by Aspora and, unless otherwise required by applicable law, is governed by the laws of England and Wales, without regard to conflict-of-laws principles. Nothing in this policy limits any rights you have under mandatory local law.
- Entire policy. This document is the complete statement of the program terms and supersedes any prior understanding regarding it.
13. Contact
- Vulnerability reports & questions: security@aspora.com
- PGP key: available on request (recommended for sensitive reports)
Aspora is a trading name of Real Transfer Limited and affiliated entities. This program covers Aspora-operated assets only; it does not extend to the systems of our regulated banking, payment, or exchange partners.
