At infinID, we are committed to maintaining the security of our platforms and protecting our users. We invite security researchers to help us
by identifying vulnerabilities and reporting them through our Bug Bounty Program.
Program Overview
The infinID Bug Bounty Program encourages ethical hackers to report security vulnerabilities that could affect infinID’s services. We offer
rewards for validated reports based on the severity and impact of the vulnerability.
Scope
The following platforms are within scope:
Out of Scope:
Reward Structure
Rewards are based on the severity of the reported vulnerability. infinID follows the CVSS (Common Vulnerability Scoring System) to
determine the impact level of each submission. Here is the reward breakdown:
Severity Level | CVSS Score Range | Example Vulnerabilities | Tables Reward Range |
Critical | 9.0-10.0 | Remote Code Execution, Privilege Escalation | IDR 4,000,000 |
High | 7.0-8.9 | SQL Injection, Authentication Bypass | IDR 3,000,000 |
Medium | 4.0-6.9 | Cross-Site Scripting (XSS), Sensitive Data Exposure | IDR 1,500,000 |
Low | 0.1-3.9 | Minor Security Misconfigurations, Information Disclosure | IDR 500,000 |
Informational | N/A | Issues that do not pose a direct security threat but are worth noting | None (IDR 0) |
The reward amounts may vary based on the actual impact of the vulnerability and how easily it can be exploited.
Vulnerability Types
We are interested in reports for the following types of vulnerabilities:
Reporting Guidelines
Responsible Disclosure Policy
We require all researchers to:
How to Submit
Submit your findings via email at [email protected]. Ensure your report includes all necessary details for reproduction.
Legal
Participation in infinID’s Bug Bounty Program implies agreement with all applicable laws. infinID reserves the right to modify or cancel the
program at any time.
Jl. RS Fatmawati Raya No. 16 Cipete Selatan, Cilandak, Jakarta Selatan, DKI Jakarta 12420, Jakarta Selatan, DKI Jakarta 12420
PT Inovasi Finansial untuk Indonesia (infinID) adalah perusahaan berbadan hukum di Indonesia yang sudah disahkan oleh Kementerian Hukum dan HAM, serta sudah resmi terdaftar sebagai Penyelenggara Sistem Elektronik (PSE) Domestik di Kementerian Komunikasi dan Informatika dengan nomor izin 008554.01/DJAI.PSE/11/2022.
infinID juga sudah resmi tercatat sebagai Penyelenggara Inovasi Keuangan Digital (IKD) di Otoritas Jasa Keuangan (OJK) pada klaster Financing Agent dengan nomor S-135/NB.22/2023, serta merupakan anggota AFTECH Indonesia dengan nomor anggota 680/REG/AFT/SU.
Kontak Perlindungan Konsumen | Direktorat Jenderal Perlindungan Konsumen dan Tata Tertib Niaga | Kementerian Perdagangan Republik Indonesia | Nomor Whatsapp: 0853 1111 1010