Product Security
Moneytree runs a fully managed bug bounty programme on Bugcrowd ↗ . Security researchers are invited to test the staging environment and responsibly disclose findings. All submissions are triaged within 8 days on average.
Reward tiers (USD)
| Priority | Severity | Reward range |
|---|---|---|
| P1 | Critical | $4,000 – $5,000 |
| P2 | High | $2,000 – $3,000 |
| P3 | Medium | $700 – $1,500 |
| P4 | Low | $300 – $500 |
In-scope targets (staging)
| Target | Type |
|---|---|
| Moneytree Web (app-staging.getmoneytree.jp) | Website |
| Moneytree Universal Vault (vault-staging.getmoneytree.com) | Website |
| Moneytree Interest Robot | Website |
| app-staging.getmoneytree.com | Website |
| Moneytree Web for Mobile | Website |
| Moneytree MyAccount (myaccount-staging.getmoneytree.com) | Website |
| Moneytree Business (business-staging.getmoneytree.com) | Website |
| Moneytree API (ap-api.getmoneytree.com) | API |
| Moneytree Android App (staging) | Mobile — Android |
| Moneytree iOS App (production) | Mobile — iOS |
Programme statistics
Testing of Moneytree KK between 21 Nov 2017 and 10 Jun 2026 still active. During this time, 1,643 researchers submitted a total of 2,884 vulnerability submissions.
| Severity | Count | Share |
|---|---|---|
| Critical | 4 | 0.1% |
| Severe | 14 | 0.5% |
| Moderate | 19 | 0.7% |
| Low | 63 | 2.2% |
| Informational | 462 | 16.0% |
| Not Applicable | 2322 | 80.5% |
| Total submissions | 2,884 |
In addition to the continuous bug bounty programme, Moneytree commissions a full internal penetration test at least once per year. Findings are tracked to remediation and results are reviewed by the Information Security Committee.
Access Control & Identity
- ✓ Policies for access control
Rules for access control based on business and information security requirements shall be established, documented, and reviewed.
ISO 27001 A.5.15 - ✓ Identity management
Processes for the full life cycle of digital identities—registration, provisioning, maintenance, and de-registration—shall be established and managed.
ISO 27001 A.5.16 - ✓ Authentication information management
Allocation and management of authentication information shall be controlled through a formal process, protecting credentials from disclosure.
ISO 27001 A.5.17 - ✓ Access rights provisioning and review
Access rights to information and associated assets shall be provisioned, reviewed, modified, and removed in line with the access control policy.
ISO 27001 A.5.18 - ✓ Privileged access rights
Privileged access rights shall be restricted, allocated on a need-to-use basis, and regularly reviewed.
ISO 27001 A.8.2 - ✓ Information access restriction
Access to information and application system functions shall be restricted in accordance with the access control policy.
ISO 27001 A.8.3 - ✓ Access to source code
Read and write access to source code, development tools, and software libraries shall be appropriately managed.
ISO 27001 A.8.4 - ✓ Secure authentication
Secure authentication technologies and procedures shall be implemented based on information access restrictions.
ISO 27001 A.8.5 · FISC 22 - ✓ User endpoint device security
Information stored on, processed by, or accessible via user endpoint devices shall be protected.
ISO 27001 A.8.1 - ✓ Use of privileged utility programs
Use of utility programs capable of overriding system and application controls shall be restricted and tightly controlled.
ISO 27001 A.8.18 - ✓ Physical entry controls
Secure areas shall be protected by appropriate entry controls to restrict access to authorised personnel only.
ISO 27001 A.7.2 - ✓ API system access authentication
Authentication shall be implemented on all system access points, preventing unauthorised access to information assets.
FISC 22 - ✓ API authentication and authorisation functions
Authentication and authorisation functions shall be developed to protect users, with countermeasures against leakage of confidential information related to authentication and authorisation.
FISC 32 · FISC 36 - ✓ API token and OAuth controls
API access tokens issued to connection partners shall be managed to ensure user accounts are not used without the user's knowledge, using OAuth 2.0 or equivalent standards.
FISC 37 · FISC 39 - ✓ Multi-factor authentication for API users
Authentication strength shall strike a suitable balance between user convenience and protection commensurate with risk, including multi-factor authentication where appropriate.
FISC 40 - ✓ Unauthorised access prevention from within
Countermeasures shall be implemented to prevent unauthorised access to information assets by internal personnel.
FISC 21 - ✓ Individual data subject access rights
Personal information handlers shall disclose held personal data to the data subject upon request without delay, in their requested format.
APPI Art.33
Data Protection & Privacy
- ✓ Privacy and protection of personally identifiable information (PII)
Privacy and protection of PII shall be ensured as required by applicable legislation and regulations.
ISO 27001 A.5.34 · APPI Art.23 - ✓ Information classification
Information shall be classified according to legal requirements, value, criticality, and sensitivity to unauthorised disclosure or modification.
ISO 27001 A.5.12 - ✓ Labelling of information
An appropriate set of procedures for information labelling shall be developed and implemented in accordance with the information classification scheme.
ISO 27001 A.5.13 - ✓ Information transfer controls
Rules, procedures, and agreements for transfer of information shall be in place for all types of transfer facilities.
ISO 27001 A.5.14 - ✓ Information deletion
Information stored in information systems, devices, or other storage media shall be deleted when no longer required.
ISO 27001 A.8.10 · APPI Art.35 - ✓ Data masking
Data masking shall be used in accordance with the organisation's topic-specific policy on access control and business requirements, and applicable legislation.
ISO 27001 A.8.11 - ✓ Data leakage prevention
Data leakage prevention measures shall be applied to systems, networks, and endpoint devices that process, store, or transmit sensitive information.
ISO 27001 A.8.12 · FISC 30 - ✓ Storage media management
Procedures shall be implemented for the management of removable media, and disposal of media shall be done securely when no longer required.
ISO 27001 A.7.10 - ✓ Secure disposal or re-use of equipment
Equipment containing storage media shall be verified that all sensitive data and licensed software has been removed or securely overwritten prior to disposal or re-use.
ISO 27001 A.7.14 · FISC 6 - ✓ Protection of records
Records shall be protected from loss, destruction, falsification, unauthorised access, and unauthorised release.
ISO 27001 A.5.33 - ✓ Sensitive personal information — acquisition restrictions
Sensitive personal information (requiring special care) shall not be acquired without obtaining the data subject's prior consent, except in legally prescribed circumstances.
APPI Art.20 - ✓ Security management measures for personal data
Personal information handlers shall take necessary and appropriate measures to prevent leakage, loss, or damage of personal data and manage its security.
APPI Art.23 - ✓ Employee supervision for personal data security
Necessary supervision shall be exercised over employees handling personal data to ensure its secure management.
APPI Art.24 - ✓ Supervision of entrusted processors
When personal data handling is entrusted to a third party, necessary supervision shall be exercised over the entrustee to ensure secure data management.
APPI Art.25 - ✓ Restrictions on third-party provision of personal data
Personal data shall not be provided to third parties without the data subject's consent, except in legally prescribed circumstances.
APPI Art.27 - ✓ Overseas transfers of personal data
Prior to transferring personal data to a foreign country, explicit consent must be obtained or an equivalent protection standard confirmed; data subjects must be informed of conditions in the foreign country.
APPI Art.28 - ✓ Record-keeping for third-party data provision
Records of all third-party personal data provisions and receipts must be maintained, including dates, recipient/provider details, and data categories.
APPI Art.29 · APPI Art.30 - ✓ Anonymization and pseudonymization standards
Personal data processed into anonymized or pseudonymized form must meet Cabinet Order standards ensuring non-identification; re-identification attempts are prohibited.
APPI Art.41 · APPI Art.43 · APPI Art.45 - ✓ Data management classification and handling rules
Management measures shall be implemented suited to the types and contents of data, including confidential information such as PINs, passwords, and biometric data.
FISC 29 - ✓ Confidential information protection in transit
Countermeasures shall be implemented against leakage of confidential information, including management of information taken off premises.
FISC 28 · FISC 30 - ✓ Information backup and restoration
Backup copies of information and software shall be taken and tested regularly; procedures shall enable restoration of lost or damaged information.
ISO 27001 A.8.13 · FISC 31 - ✓ Right to correction of personal data
Upon request, personal information handlers shall investigate and correct inaccurate personal data held about the data subject.
APPI Art.34 - ✓ Disclosure of personal information handling practices
Businesses shall make accessible to data subjects the business name, purposes of use, and complaint procedures for held personal data.
APPI Art.32
Application Security
- ✓ Secure development life cycle
Rules for the secure development of software and systems shall be established and applied to developments within the organisation.
ISO 27001 A.8.25 - ✓ Application security requirements
Information security requirements shall be identified, specified, and approved when developing or acquiring applications.
ISO 27001 A.8.26 - ✓ Secure system architecture and engineering principles
Principles for engineering secure systems shall be established, documented, maintained, and applied to any information system implementation.
ISO 27001 A.8.27 - ✓ Secure coding practices
Secure coding principles shall be applied to software development, covering common vulnerabilities such as injection attacks and buffer overflows.
ISO 27001 A.8.28 · FISC 27 - ✓ Security testing in development and acceptance
Security testing processes shall be defined and implemented in the development life cycle.
ISO 27001 A.8.29 - ✓ Outsourced development security
The organisation shall supervise and monitor the activity related to outsourced system development.
ISO 27001 A.8.30 - ✓ Separation of development, test, and production environments
Development, testing, and production environments shall be separated and protected to reduce the risk of unauthorised access or changes.
ISO 27001 A.8.31 - ✓ Change management
Changes to information processing facilities and information systems shall be subject to change management procedures.
ISO 27001 A.8.32 - ✓ Test information protection
Test information shall be selected carefully, protected, and controlled; production data containing personal information shall not be used for testing without appropriate masking.
ISO 27001 A.8.33 - ✓ Protection of information systems during audit testing
Audit tests and other assurance activities involving assessment of operational systems shall be planned and agreed upon to minimise disruptions.
ISO 27001 A.8.34 - ✓ Management of technical vulnerabilities
Information about technical vulnerabilities shall be obtained, exposure evaluated, and appropriate measures taken including patch management.
ISO 27001 A.8.8 · FISC 27 - ✓ Software installation controls on operational systems
Procedures shall be implemented to control the installation of software on operational systems.
ISO 27001 A.8.19 - ✓ Countermeasures against fake/malicious applications
Countermeasures shall be implemented against fake applications distributed through unofficial channels that impersonate legitimate service applications.
FISC 33 - ✓ API unexpected usage prevention
Controls shall prevent unexpected usage of APIs, including enforcement of rate limits, scope restrictions, and input validation.
FISC 37 - ✓ Multilayered attack protection for APIs
Multilayered protection shall be implemented against attacks targeting API vulnerabilities, including WAF, IDS/IPS, and DMZ architecture.
FISC 41 - ✓ Limit damage from unauthorised access
Controls shall limit the spread of damage from unauthorised access; tracing mechanisms shall enable investigation following security incidents.
FISC 34 · FISC 35 - ✓ Web filtering
Access to external websites shall be managed to protect users from web-based threats and malicious content.
ISO 27001 A.8.23 - ✓ Use of cryptography
A policy on the use of cryptographic controls, including key management, shall be developed and implemented to protect information.
ISO 27001 A.8.24
Infrastructure & Network Security
- ✓ Network security management
Networks and network devices shall be managed and controlled to protect information in systems and applications.
ISO 27001 A.8.20 - ✓ Security of network services
Security mechanisms, service levels, and management requirements for network services shall be identified and included in agreements.
ISO 27001 A.8.21 - ✓ Segregation of networks
Groups of information services, users, and information systems shall be segregated in the organisation's networks.
ISO 27001 A.8.22 - ✓ Configuration management
Configurations, including security configurations, of hardware, software, services, and networks shall be established, documented, implemented, monitored, and reviewed.
ISO 27001 A.8.9 - ✓ Protection against malware
Protection against malware shall be implemented and supported by appropriate user awareness measures.
ISO 27001 A.8.7 · FISC 20 - ✓ Capacity management
The use of resources shall be monitored and adjusted to meet current and future capacity requirements.
ISO 27001 A.8.6 - ✓ Redundancy of information processing facilities
Information processing facilities shall be implemented with sufficient redundancy to meet availability requirements.
ISO 27001 A.8.14 - ✓ Logging and monitoring
Event logs recording user activities, exceptions, faults, and information security events shall be produced, retained, and regularly reviewed.
ISO 27001 A.8.15 · ISO 27001 A.8.16 · FISC 23 - ✓ Clock synchronisation
The clocks of information processing systems shall be synchronised to an approved time source.
ISO 27001 A.8.17 - ✓ Physical security perimeters
Security perimeters shall be defined and used to protect areas that contain information and other associated assets.
ISO 27001 A.7.1 · FISC 17 - ✓ Physical security monitoring
Premises shall be continually monitored for unauthorised physical access.
ISO 27001 A.7.4 - ✓ Protection against physical and environmental threats
Protection against physical and environmental threats such as natural disasters, accidents, and deliberate attacks shall be designed and implemented.
ISO 27001 A.7.5 - ✓ Supporting utilities protection
Information processing facilities shall be protected from power failures and other disruptions caused by failures in supporting utilities.
ISO 27001 A.7.11 - ✓ Cabling security
Cables carrying power, data, or supporting information services shall be protected from interception, interference, or damage.
ISO 27001 A.7.12 - ✓ Equipment maintenance
Equipment shall be maintained correctly to ensure availability, integrity, and confidentiality of information.
ISO 27001 A.7.13 - ✓ Unauthorised external access countermeasures
Countermeasures against unauthorised access from the outside shall be implemented, including firewalls, IDS/IPS, and DMZ architecture.
FISC 26 - ✓ Computer facility physical security
Countermeasures against information leakage from computer facilities shall be implemented, restricting entry of unauthorised persons and access to important information.
FISC 17 · FISC 18 - ✓ Office facility security controls
Physical security shall be ensured in office facilities, preventing unauthorised persons from entering and restricting removal of important information from premises.
FISC 18 · FISC 19
Incident Response & Business Continuity
- ✓ Information security incident management planning
The organisation shall plan and prepare for managing information security incidents, defining responsibilities and procedures.
ISO 27001 A.5.24 · FISC 7 - ✓ Assessment and decision on security events
Information security events shall be assessed and it shall be decided if they are to be classified as information security incidents.
ISO 27001 A.5.25 - ✓ Response to information security incidents
Information security incidents shall be responded to in accordance with documented procedures.
ISO 27001 A.5.26 · FISC 7 - ✓ Learning from information security incidents
Knowledge gained from analysing and resolving information security incidents shall be used to reduce the likelihood or impact of future incidents.
ISO 27001 A.5.27 - ✓ Collection of evidence
The organisation shall define and apply procedures for the identification, collection, acquisition, and preservation of evidence related to information security incidents.
ISO 27001 A.5.28 - ✓ Information security during disruption
The organisation shall determine requirements for information security and continuity of information security management during an adverse situation.
ISO 27001 A.5.29 - ✓ ICT readiness for business continuity
ICT readiness shall be planned, implemented, maintained, and tested to ensure the availability of information and other assets during a disruption.
ISO 27001 A.5.30 - ✓ Information security event reporting
The organisation shall provide a mechanism for personnel to report observed or suspected information security events.
ISO 27001 A.6.8 - ✓ Breach notification to PPC and data subjects
In the event of a data breach or potential breach involving personal data, the incident must be reported to the Personal Information Protection Commission and affected individuals notified promptly (preliminary report within 3-5 days; final report within 30 days).
APPI Art.26 - ✓ API incident preparation and response
Preparations shall be made for incidents such as unauthorised access and system failures; appropriate responses shall be implemented in the event of a security incident to prevent spread of damage.
FISC 9 · FISC 7 - ✓ User damage prevention and compensation
Measures shall be implemented to prevent spread of damage to users; users shall be compensated appropriately when needed; contact points for user compensation shall operate properly.
FISC 14 · FISC 15 · FISC 16 - ✓ User inquiry and complaint handling
Appropriate responses shall be implemented to requests, inquiries, and other contacts from users regarding security incidents and service disruptions.
FISC 13
Governance, Risk & Compliance
- ✓ Information security policies
An information security policy and topic-specific policies shall be defined, approved by management, published, communicated to, and acknowledged by relevant personnel.
ISO 27001 A.5.1 · FISC 2 - ✓ Information security roles and responsibilities
Information security responsibilities shall be defined and allocated according to the organisation's needs.
ISO 27001 A.5.2 · FISC 1 - ✓ Segregation of duties
Conflicting duties and conflicting areas of responsibility shall be segregated to reduce opportunities for unauthorised or unintentional modification or misuse of assets.
ISO 27001 A.5.3 - ✓ Management responsibilities
Management shall require all personnel to apply information security in accordance with the established policy and procedures.
ISO 27001 A.5.4 - ✓ Contact with authorities and special interest groups
Appropriate contacts with relevant authorities and special interest groups shall be maintained regarding information security.
ISO 27001 A.5.5 · ISO 27001 A.5.6 - ✓ Threat intelligence
Information relating to information security threats shall be collected and analysed to produce threat intelligence.
ISO 27001 A.5.7 - ✓ Information security in project management
Information security shall be integrated into project management.
ISO 27001 A.5.8 - ✓ Inventory of information and associated assets
An inventory of information and other associated assets, including owners, shall be developed and maintained.
ISO 27001 A.5.9 · FISC 4 - ✓ Acceptable use of information and assets
Rules for the acceptable use and procedures for handling information and other associated assets shall be identified, documented, and implemented.
ISO 27001 A.5.10 - ✓ Return of assets
Personnel and other interested parties shall return all the organisation's assets in their possession upon change or termination of employment, contract, or agreement.
ISO 27001 A.5.11 - ✓ Information security in supplier relationships
Processes and procedures shall be defined and implemented to manage the information security risks associated with the use of supplier's products or services.
ISO 27001 A.5.19 - ✓ Information security in supplier agreements
Relevant information security requirements shall be established and agreed upon with each supplier based on the type of supplier relationship.
ISO 27001 A.5.20 - ✓ ICT supply chain security
Processes and procedures shall be defined and implemented to manage the information security risks associated with the ICT products and services supply chain.
ISO 27001 A.5.21 - ✓ Monitoring and review of supplier services
The organisation shall regularly monitor, review, evaluate, and manage change in supplier information security practices and service delivery.
ISO 27001 A.5.22 - ✓ Cloud service security
Processes for acquiring, using, managing, and exiting cloud services shall be established, in line with the organisation's information security requirements.
ISO 27001 A.5.23 · FISC 11 - ✓ Legal, statutory, regulatory, and contractual requirements
All relevant legal, regulatory, statutory, and contractual requirements shall be identified, documented, and kept up to date for each information system.
ISO 27001 A.5.31 - ✓ Intellectual property rights
Appropriate procedures shall be implemented to protect intellectual property rights.
ISO 27001 A.5.32 - ✓ Independent review of information security
The organisation's approach to managing information security shall be reviewed independently at planned intervals or when significant changes occur.
ISO 27001 A.5.35 - ✓ Compliance with policies and standards
Compliance with the organisation's information security policy, topic-specific policies, and standards shall be regularly reviewed.
ISO 27001 A.5.36 - ✓ Documented operating procedures
Operating procedures for information processing facilities shall be documented and made available to all users who need them.
ISO 27001 A.5.37 - ✓ Personnel screening
Background verification checks on all candidates for employment shall be carried out prior to joining the organisation.
ISO 27001 A.6.1 - ✓ Terms and conditions of employment
Employment contractual agreements shall state the personnel's and the organisation's responsibilities for information security.
ISO 27001 A.6.2 - ✓ Security awareness, education, and training
All personnel shall receive appropriate security awareness education and training relevant to their roles.
ISO 27001 A.6.3 · FISC 3 - ✓ Disciplinary process for security violations
A disciplinary process shall be formalised and communicated to take action against personnel and other parties who have committed an information security policy violation.
ISO 27001 A.6.4 - ✓ Confidentiality and non-disclosure agreements
Requirements for confidentiality or non-disclosure agreements reflecting the organisation's needs for the protection of information shall be identified and regularly reviewed.
ISO 27001 A.6.6 - ✓ Remote working security
Security measures shall be implemented when personnel are working remotely to protect information accessed, processed, or stored outside the organisation's premises.
ISO 27001 A.6.7 - ✓ Outsourcing management
Measures shall be implemented to ensure effective and proper execution of outsourced operations, including oversight of chain connection partners.
FISC 10 · FISC 8 - ✓ Security governance establishment and monitoring
Governance of security management shall be firmly established through ensuring all executives and employees understand information management methods and through regular follow-up monitoring and auditing.
FISC 3 · FISC 12 - ✓ API user accountability and transparency
Accountability to users regarding their API use shall be ensured; users must not be subject to misconceptions or misunderstandings regarding API connections.
FISC 43 · FISC 44 - ✓ Misconduct prevention controls
Measures shall be implemented to prevent misconduct by executives, employees, and operators, including operator countermeasures and separation of duties.
FISC 5 · FISC 24 - ✓ System change management controls
Measures shall be implemented to prevent marked deterioration in quality when making changes to systems, following a controlled change management process.
FISC 25 - ✓ Security review and continuous improvement
Security measures shall be regularly reviewed and improved in accordance with changes in the threat landscape, operational environment, and regulatory requirements.
FISC 12
Last updated: June 2026