Responsible Disclosure

Last updated: 3 August 2017

Print

Responsible Disclosure

We take the security of our clients’ data very seriously, and strongly encourage anyone who thinks they have discovered a potential security vulnerability in any of our services to disclose it to us responsibly.

We appreciate the assistance of security researchers and are happy to work with them to validate and respond to vulnerabilities that are reported to us in a responsible manner. However, we do not tolerate any of the following, which will be reported to the appropriate authorities and may incur legal action:

  • Any attempt to access or modify other people’s data.
  • Any attempt to execute a denial of service attack.
  • Any attempt to interrupt or degrade the service we offer our customers.
  • Any testing against third-party websites, applications or services that integrate with our services.
  • Knowingly sending, uploading, transmitting, or linking to any malware, virus or similar harmful software.
  • Any testing that involves violation of any applicable law.

Reporting potential vulnerabilities

Please share the details of any suspected vulnerability with us by sending email to our security team at [email protected]. You should include as much information as possible in your report, including how we can reproduce the issue.

Our commitment

For all researchers following this Responsible Disclosure Policy, we commit to:

  • Acknowledge receipt of your email in a timely fashion.
  • Provide an estimated time-frame for addressing the vulnerability.
  • Notify you when the vulnerability is fixed.

Compensation

We do not offer compensation to individuals or organizations for identifying potential or confirmed security vulnerabilities, and requests for monetary compensation will be treated as a breach of this Responsible Disclosure Policy.

Donation to charity

Although we do not offer monetary compensation, if we feel that the vulnerability is significant we will show our appreciation by making a donation on your behalf to your choice of these charities:

  • International Federation of Red Cross and Red Crescent Societies
  • Médecins sans Frontières (Doctors Without Borders)
  • Water Aid
  • World Wildlife Fund
  • Save the Children
  • Survival International
  • Sightsavers

 

Hall of Fame

Currencycloud would like to acknowledge and thank the following people for helping us to improve our security:

Reporter Date Contact

Jolan Saluria

21 May 2017

Abhishek Sidharth

21 May 2017

Sreedeep Alavil

4 May 2017 Facebook

Ketankumar Godhani

22 April 2017 Twitter

Latest Releases

PSD2 and GDPR: Conflicting regulations?

PSD2 came into force in January 2018, while the GDPR deadline is May. How can the two seemingly different regulations work together? This year marks the arrival of two important EU regulations that will impact the financial sector: The update to the general data...

Protecting data: Who must comply with EU GDPR?

The update to data protection regulation is coming. Who, exactly, needs to comply? There will be huge implications for anyone that does not adequately protect personal data when the EU update to data protection regulation (GDPR) comes into place in just three months’...

Open Banking: Ignore the mainstream media

Open Banking came into force on 13 January and was met with a caterwauling chorus of cynicism by the mainstream media. Hysterical headlines about hucksters andfraudsters were the order of the day, with claims that consumers are “fearful and confused” after an anaemic...