Product Security

🐛
Bug Bounty Programme — Bugcrowd

Moneytree runs a fully managed bug bounty programme on Bugcrowd ↗ . Security researchers are invited to test the staging environment and responsibly disclose findings. All submissions are triaged within 8 days on average.


Reward tiers (USD)

PrioritySeverityReward range
P1 Critical $4,000 – $5,000
P2 High $2,000 – $3,000
P3 Medium $700 – $1,500
P4 Low $300 – $500

In-scope targets (staging)

TargetType
Moneytree Web (app-staging.getmoneytree.jp)Website
Moneytree Universal Vault (vault-staging.getmoneytree.com)Website
Moneytree Interest RobotWebsite
app-staging.getmoneytree.comWebsite
Moneytree Web for MobileWebsite
Moneytree MyAccount (myaccount-staging.getmoneytree.com)Website
Moneytree Business (business-staging.getmoneytree.com)Website
Moneytree API (ap-api.getmoneytree.com)API
Moneytree Android App (staging)Mobile — Android
Moneytree iOS App (production)Mobile — iOS

Programme statistics

Testing of Moneytree KK between 21 Nov 2017 and 10 Jun 2026 still active. During this time, 1,643 researchers submitted a total of 2,884 vulnerability submissions.

SeverityCountShare
Critical 4 0.1%
Severe 14 0.5%
Moderate 19 0.7%
Low 63 2.2%
Informational 462 16.0%
Not Applicable 2322 80.5%
Total submissions 2,884
🔍
Annual Penetration Test

In addition to the continuous bug bounty programme, Moneytree commissions a full internal penetration test at least once per year. Findings are tracked to remediation and results are reviewed by the Information Security Committee.

Last updated: June 2026