Last updated: 24 October 2024
Pintu (hereinafter referred to as Pintu, we, our, us) is Indonesia’s leading Blockchain technology company. We are a strong Indonesian and International team passionate about using blockchain to drive positive change in Indonesia.
Here at Pintu, we take security seriously and understand the importance and value that external security researchers can bring. Thus we invite external security researchers (hereinafter referred to as the reporter, you) to report any security issues on our assets. We will investigate all the reports sent to us and seek to reward the reports that meet our reward criteria and follow our disclosure policy.Â
No technology is perfect and Pintu believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We look forward to receiving reports from you to keep our customers and businesses safe.
By joining, accessing, and participating in the Bug Bounty Program (“Program”), the reporter agrees to comply with and will be bound to all the policies, terms, and conditions as written in this Program Policy (“Policy”) and acknowledge that this Policy constitutes a legally binding agreement between you and Pintu. If the reporter does not agree to the Policy, the Reporter may stop accessing, participating, and/or joining the Program. Â
For all the reports that are sent to us, we require the reporter to follow our following disclosure policy:
We will make the best effort to meet the following SLAs for researchers participating in our program:

We’ll try to keep you informed about our progress throughout the process.
The reporters are prohibited from performing the following actions:
To be deemed valid, a report must demonstrate a vulnerability in a service provided by Pintu that harms Pintu or Pintu customers. Reports that include a clear Proof of Concept or specific step-by-step instructions to replicate the vulnerability are considerably more effective at communicating a researcher’s findings and are therefore far more likely to be deemed valid.
To qualify for a bounty, a report must contain vulnerabilities and assets that are listed in scope. Pintu awards bounties based on the severity of the vulnerability based on two factors: Impact and Exploitability.
Impact describes the effects of successful exploitation upon Pintu systems or customers. We make this assessment primarily by examining the effects of exploitation on confidentiality, integrity, or availability of underlying information.
Vulnerabilities that require considerable response and remediation efforts or could result in reputational damage are also considered to have a greater impact.
Only vulnerabilities with a working proof of concept showing how they can be exploited and vulnerabilities with a real security impact will be considered eligible for monetary rewards. Determination of whether a reported issue sufficiently meets the bar for monetary rewards is done at Pintu’s discretion.
The details of the rewards for reporters who meet the terms and conditions of this Policy (“Eligible Reporters“) are as follows:

For the avoidance of doubt, Pintu and the reporter shall be responsible for their own tax obligations arising from any rewards provided in this Program.


Below are the types of submissions that are preferred to be accepted
Reporters who conduct activities in a manner that is consistent and compliant with the above policy will be considered authorized individuals or entities, Pintu will not initiate any legal action against them.
For Indonesian
The payment process may take up to 2 weeks from when Pintu decides the reporter is eligible to get the reward and will be made through Indonesian Banks.
Bank account and personal details will be requested to process the payment and legal purposes.
For Others
The payment process may take up to 1 month from when Pintu decides the reporter is eligible to get the reward and will be made through USDT over Ethereum or Polygon network.
Receiving wallet address and personal details will be requested to process the payment and legal purposes.
By joining the program, besides all the terms and conditions as stated in the Policy above, the reporter agrees to follow the terms and conditions as follows: