Kredivo · Vulnerability Disclosure

Kredivo Vulnerability Disclosure

Vulnerability disclosure

Kredivo runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyPaymentsBuy Now Pay LaterBNPLLendingConsumer CreditCheckoutFintechEcommerceIndonesiaSoutheast AsiaFinancial Services
Program: Hackerone

Disclosure Policy

Security Contact

Contact
evidenceThe published security policy page directs security inquiries to security@kredivo.com. This is a real, dedicated security address — the only documented route for reporting a vulnerability — but it is presented as a general security contact rather than as a disclosure intake channel.
Contact
other_contacts{"email" => "support@kredivo.com", "hours" => "Monday–Sunday, 08:00–20:00", "purpose" => "General consumer support"}{"email" => "hello@kredivo.com", "phone" => "021-2205-5677", "purpose" => "Company inquiries"}
Contact
security_emailsecurity@kredivo.com
Contact
sourcehttps://kredivo.com/security-policy/

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
source: https://kredivo.com/security-policy/
api: Kredivo
summary: |
  Kredivo publishes a human-readable security policy page with a dedicated security contact address,
  but no formal vulnerability disclosure program. The automated probe pass (probe-security-programs.py)
  returned no hit because there is no security.txt and no page matching the standard
  responsible-disclosure patterns; this file records what a manual search of the published security
  surface actually found on 2026-07-19.
program:
  formal_vdp: false
  bug_bounty: false
  safe_harbor:
    published: false
  scope:
    published: false
  disclosure_policy:
    published: false
  note: |
    No responsible-disclosure policy, no defined scope, no safe-harbor language, no coordinated
    disclosure timeline and no researcher acknowledgements. Kredivo is not listed on HackerOne,
    Bugcrowd or Intigriti as far as the public surface shows.
contact:
  security_email: security@kredivo.com
  source: https://kredivo.com/security-policy/
  evidence: |
    The published security policy page directs security inquiries to security@kredivo.com. This is a
    real, dedicated security address — the only documented route for reporting a vulnerability — but
    it is presented as a general security contact rather than as a disclosure intake channel.
  other_contacts:
  - purpose: General consumer support
    email: support@kredivo.com
    hours: Monday–Sunday, 08:00–20:00
  - purpose: Company inquiries
    email: hello@kredivo.com
    phone: 021-2205-5677
security_txt:
  published: false
  probed: '2026-07-19'
  hosts_probed:
  - https://kredivo.com/.well-known/security.txt
  - https://kredivo.com/security.txt
  - https://doc.kredivo.com/.well-known/security.txt
  - https://sandbox.kredivo.com/.well-known/security.txt
  - https://finaccel.co/.well-known/security.txt
  - https://kredivocorp.com/.well-known/security.txt
  result: 404 on every host
  note: |
    Publishing an RFC 9116 security.txt pointing at security@kredivo.com would be a near-zero-cost
    improvement — the contact already exists, it is simply not machine-discoverable.
published_security_page:
  url: https://kredivo.com/security-policy/
  probed_status: 200
  linked_from: kredivo.com footer ("Kebijakan Keamanan")
  controls_described:
  - Two-factor authentication
  - Encryption in transit and at rest
  - Secure storage and backups
  - Protection against DDoS and MITM attacks
  - Strict internal access controls
  referenced_documents:
  - name: Security, Privacy and Architecture (SPARC) Documentation
    description: |
      Referenced from the security policy page as covering security protocols, technical
      infrastructure and privacy practices. Not independently verified as publicly accessible.
  note: |
    The controls are described in prose only. No certification is named, no attestation report is
    offered and no trust center exists. See conformance/kredivo-conformance.yml.
gaps:
- No formal vulnerability disclosure policy or coordinated disclosure process.
- No bug bounty program.
- No safe-harbor commitment for good-faith researchers.
- No RFC 9116 security.txt, so the existing security contact is not machine-discoverable.
- No published response-time commitment for security reports.