Product Security
Moneytree maintains 63 security controls across five domains. Each control is reviewed annually and validated through independent audits.
- Unique production database authentication enforced
- Encryption key access restricted
- Unique account authentication enforced
- Asset disposal procedures utilized
- Production inventory maintained
- Portable media encrypted
- Control self-assessments conducted
- Penetration testing performed
- Vulnerability scanning performed
- Continuity and Disaster Recovery plans established
- Continuity and disaster recovery plans tested
- Cybersecurity insurance maintained
- Data retention procedures established
- Customer data deleted upon leaving
- Data classification policy established
Moneytree runs a fully managed bug bounty programme on Bugcrowd ↗. Security researchers are invited to test the staging environment and responsibly disclose findings. All submissions are triaged within 8 days on average.
Reward tiers (USD)
| Priority | Severity | Reward range |
|---|---|---|
| P1 | Critical | $4,000 – $5,000 |
| P2 | High | $2,000 – $3,000 |
| P3 | Medium | $700 – $1,500 |
| P4 | Low | $300 – $500 |
In-scope targets (staging)
| Target | Type |
|---|---|
| Moneytree Web (app-staging.getmoneytree.jp) | Website |
| Moneytree Universal Vault (vault-staging.getmoneytree.com) | Website |
| Moneytree Interest Robot | Website |
| app-staging.getmoneytree.com | Website |
| Moneytree Web for Mobile | Website |
| Moneytree MyAccount (myaccount-staging.getmoneytree.com) | Website |
| Moneytree Business (business-staging.getmoneytree.com) | Website |
| Moneytree API (ap-api.getmoneytree.com) | API |
| Moneytree Android App (staging) | Mobile — Android |
| Moneytree iOS App (production) | Mobile — iOS |
Programme statistics
Testing of Moneytree KK between 21 Nov 2017 and 10 Jun 2026. During this time, 1,643 researchers submitted a total of 2,884 vulnerability submissions.
| Severity | Count | Share |
|---|---|---|
| Critical | 4 | 0.1% |
| Severe | 14 | 0.5% |
| Moderate | 19 | 0.7% |
| Low | 63 | 2.2% |
| Informational | 462 | 16.0% |
| Not Applicable | 2,322 | 80.5% |
| Total submissions | 2,884 |
In addition to the continuous bug bounty programme, Moneytree commissions a full internal penetration test at least once per year. Findings are tracked to remediation and results are reviewed by the Information Security Committee.