Boku · Vulnerability Disclosure

Boku Vulnerability Disclosure

Vulnerability disclosure

Boku runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyPaymentsMobile PaymentsCarrier BillingDigital WalletsLocal Payment MethodsSubscriptionsFintech
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Contact
https://www.boku.com/boku-bug-bounty-program

Source

Vulnerability Disclosure

boku-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-18'
method: searched
probe: true
program: Boku Bug Bounty Program
self_hosted: true
policy:
- https://www.boku.com/boku-bug-bounty-program
- https://www.boku.com/boku-bug-bounty-terms-and-conditions/
contact:
- https://www.boku.com/boku-bug-bounty-program
notes: >-
  Boku runs a self-hosted bug bounty / responsible-disclosure program (not on
  HackerOne, Bugcrowd, or Intigriti). Researchers email findings to Boku's
  published security contact with steps to reproduce and analysis. Bounty awards
  are available for previously unknown vulnerabilities. Out of scope: unverified
  automated-scanner output, social engineering of staff, and physical attacks on
  Boku offices. A dedicated security contact address is published on the program
  page (email obfuscated on the live page — not transcribed here to avoid error).
evidence:
- source: https://www.boku.com/boku-bug-bounty-program
  kind: bug bounty / responsible disclosure program page
- source: https://www.boku.com/boku-bug-bounty-terms-and-conditions/
  kind: program terms and conditions