Abhieo
Program Details
Rules of Engagement ✅ DO: Use Your Own Accounts: Only test with accounts you own or have explicit permission to access Report First: Submit vulnerabilities to us before public disclosure Be Professional: Maintain professional and respectful communication Provide Details: Include comprehensive reproduction steps, proof of concept, and impact assessment Give Us Time: Allow reasonable time for investigation and fix (typically 90 days)
- Allows Disclosure
- No
- Disclosure Window
- 90 days
- Response SLA
- 3 business days
Payout Structure
Rules & Testing
- Requires Account
- Yes
- Testing Policy
- https://www.abhieo.in/bug-bounty
Excluded Methods
In-Scope Domains
- www.abhieo.in (Main website)
- All subdomains (*.abhieo.in)
- Web application APIs
- Payment gateways integration
- RESTful APIs
- Authentication & Authorization APIs
- Transaction processing APIs
- User management APIs
- ABHIEO Android App (Google Play Store)
- ABHIEO iOS App (Apple App Store)
- All mobile app APIs and endpoints
- Payment processing workflows
- Wallet functionality
- Transaction verification systems
- Refund mechanisms
Out of Scope
Third-party services and platforms (payment gateways, SMS providers, email services), Service Provider systems (mobile operators, DTH providers, billers), Social media profiles and pages, Physical security of ABHIEO offices, Employee email accounts (unless demonstrating a critical vulnerability), Staging/development/test environments (unless critical server-level vulnerabilities), Issues in archived or deprecated services
Security
- Preferred Languages
- English