Vulnerability Disclosure Program

At me&u, we are committed to the security and privacy of our customers' personal and financial information. We take all reports of vulnerabilities in our systems and applications seriously and appreciate the efforts of security researchers in helping us to identify and fix potential issues.

To report a vulnerability, please use the form at the end of this page, including steps to reproduce the vulnerability and any supporting documentation. If possible, please also include a suggested fix or workaround for the issue.

Upon receipt of a vulnerability report, we will acknowledge receipt of the report within 10 business days. We will then investigate the issue and provide a status update within 20 business days.

Once the issue has been resolved, we will work with the researcher to coordinate the public disclosure of the issue, if deemed appropriate by me&u. However, please note that we reserve the right to not publicly disclose the issue depending on the circumstances. We ask that researchers do not publicly disclose the issue until we have had the opportunity to address it and make a decision on public disclosure.

We will not take legal action against researchers who comply with this policy. We do, however, ask that researchers do not use any vulnerabilities they discover to harm our systems or users, or to gain unauthorised access to any data.

We also ask that researchers do not share the details of any vulnerabilities they discover with any third parties until the issue has been resolved and a decision on public disclosure has been made.

We may offer a monetary reward for significant security vulnerabilities that are reported and successfully resolved, based on the impact and difficulty of the issue. The amount of the reward will be at the discretion of me&u.

Expectations

When working with us according to this policy, you can expect:

In-Scope Vulnerabilities

The following vulnerabilities are eligible for our security program, as they significantly impact the confidentiality or integrity of user data:

While these vulnerabilities are our primary focus for security research, we are also interested in reports for all software and dependencies, especially if they affect sensitive user data. This may include open-source libraries, software, or third-party components. At our discretion, we may issue rewards for reports not included in this list.

Out-of-Scope Vulnerabilities

The following items are not eligible for rewards under our security program:

The security team at me&u is dedicated to keeping our customers and their data safe. We thank you for engaging with us on our Vulnerability Disclosure Program.

Submission form

All fields are required unless marked optional.

Summary title

Help us get an idea of what this vulnerability is about.

Submission title

Target

Select the vulnerable target

Targets that are not explicitly in scope may not be eligible for acceptance.

Target

Select target…Other

Technical severity

The Vulnerability Rating Taxonomy is the baseline guide used for classifying technical severity.

VRT Category

Select or search for a vulnerability type

VRT Subcategory (optional)

VRT Variant (optional)

Vulnerability details

URL / Location of vulnerability (optional) For example: https://secure.server.com/some/path/file.php

Description

Describe the vulnerability and its impact.

Provide a proof of concept or replication steps.

Maximum 25,000 characters.

Write in Markdown Preview Markdown

Embed images by dragging & dropping, selecting, or pasting them. Markdown supported

Attachments (optional)

Attach proof-of-concept scripts, screenshots, screen recordings, etc.

Add attachments

You can attach up to 20 files. Please keep individual upload size under 400MiB.

You can embed attachments (.jpg/.gif/.png, smaller than 5MB) into the Markdown fields. You can copy the embed code using the ‘Copy as Markdown’ button.

Email

By providing your email address you can claim your submission on bugcrowd.com.

Note: Submissions through this form are welcome. However, if you have been removed from the Bugcrowd platform or this customer’s engagements by the Platform Behavior Standards team:

This form is intended solely for anonymous ethical disclosure and cannot be used to bypass removals.

Researcher email (optional)

Confirmation

Confirm your submission is accurate and adheres to Bugcrowd’s terms & conditions.

I agree to Bugcrowd’s terms & conditions as well as any additional rules and instructions provided by the organization hosting this program

Report vulnerability