Product Security

Moneytree maintains 63 security controls across five domains. Each control is reviewed annually and validated through independent audits.

Infrastructure security
  • Unique production database authentication enforced
  • Encryption key access restricted
  • Unique account authentication enforced
+ 14 more
Organizational security
  • Asset disposal procedures utilized
  • Production inventory maintained
  • Portable media encrypted
+ 9 more
Product security
  • Control self-assessments conducted
  • Penetration testing performed
  • Vulnerability scanning performed
+ 6 more
Internal security procedures
  • Continuity and Disaster Recovery plans established
  • Continuity and disaster recovery plans tested
  • Cybersecurity insurance maintained
+ 9 more
Data and privacy
  • Data retention procedures established
  • Customer data deleted upon leaving
  • Data classification policy established
+ 10 more
🐛
Bug Bounty Programme — Bugcrowd

Moneytree runs a fully managed bug bounty programme on Bugcrowd ↗. Security researchers are invited to test the staging environment and responsibly disclose findings. All submissions are triaged within 8 days on average.


Reward tiers (USD)

PrioritySeverityReward range
P1Critical$4,000 – $5,000
P2High$2,000 – $3,000
P3Medium$700 – $1,500
P4Low$300 – $500

In-scope targets (staging)

TargetType
Moneytree Web (app-staging.getmoneytree.jp)Website
Moneytree Universal Vault (vault-staging.getmoneytree.com)Website
Moneytree Interest RobotWebsite
app-staging.getmoneytree.comWebsite
Moneytree Web for MobileWebsite
Moneytree MyAccount (myaccount-staging.getmoneytree.com)Website
Moneytree Business (business-staging.getmoneytree.com)Website
Moneytree API (ap-api.getmoneytree.com)API
Moneytree Android App (staging)Mobile — Android
Moneytree iOS App (production)Mobile — iOS

Programme statistics

Testing of Moneytree KK between 21 Nov 2017 and 10 Jun 2026. During this time, 1,643 researchers submitted a total of 2,884 vulnerability submissions.

SeverityCountShare
Critical40.1%
Severe140.5%
Moderate190.7%
Low632.2%
Informational46216.0%
Not Applicable2,32280.5%
Total submissions2,884
🔍
Annual Penetration Test

In addition to the continuous bug bounty programme, Moneytree commissions a full internal penetration test at least once per year. Findings are tracked to remediation and results are reviewed by the Information Security Committee.