Help Us Keep Unlimited Remit Secure
How it works
Find
Identify a genuine security vulnerability within the approved scope.
Report
Submit the vulnerability with clear details and steps to reproduce it.
Get Rewarded
Our security team reviews the report. If the vulnerability is valid and eligible, you may receive a reward.
Reward information
Rewards Based on Severity
| Severity | Example | Reward | |
| Critical | Serious vulnerability affecting systems or customer security | Up to $XXX | |
| High | Major security issue with significant impact | Up to $XXX | |
| Medium | Vulnerability with limited but meaningful impact | Up to $XXX | |
| Low | Minor security issue | Recognition / discretionary reward |
What Is in and out of Scope?
Eligible Systems
In Scope
- Unlimited Remit public website
- Unlimited Remit web application
- Official Unlimited Remit mobile applications
- APIs and services specifically owned and operated by Unlimited Remit
Out of Scope
- Third-party websites and services
- Payment partners or banking partner systems
- Social engineering or phishing attacks
- Physical attacks
- Denial-of-Service or stress testing
- Spam or mass messaging
- Accessing, modifying, or deleting real customer data
- Attacks that disrupt services
Please do not test vulnerabilities in a way that may affect customer funds, transactions, accounts, or the availability of our services.
CRM form will load here
What Happens After You Submit?
We aim to acknowledge valid reports as soon as possible and will keep you informed during the review process.
Step 1
Report Received
We receive your submitted form and then acknowledge it.
Step 2
Review
Our technical and security team investigates the vulnerability.
Step 3
Validation
We confirm whether the issue is valid and within the program scope.
Step 4
Resolution
Our team works to address the level of vulnerability of the bug.
Step 5
Reward
If eligible, the bounty amount is determined and payment arrangements are made.
Frequently Asked Questions
Who can participate in the Bug Bounty Program?
Anyone who follows the program rules and responsibly reports an eligible vulnerability.
Will every report receive a reward?
No. Rewards are provided for valid, eligible vulnerabilities based on severity and impact.
What if someone else has already reported the same bug?
Rewards are generally considered for the first valid report received.
Can I test using a real customer account?
Only if it is your own authorized account. You must never access another person's account or data.
Can I publicly disclose the vulnerability?
No. Please keep the vulnerability confidential until Unlimited Remit has reviewed and resolved the issue.
How will I know if my report has been accepted?
The Unlimited Remit team will contact you using the email address provided in your submission.