generated: '2026-09-02' method: searched source: https://upstox.com/bug-bounty/ name: Upstox Bug Bounty Program program: type: self-hosted name: Upstox Bug Bounty Program url: https://upstox.com/bug-bounty/ platform: none note: >- Upstox runs its own bug bounty rather than using HackerOne, Bugcrowd or Intigriti. Submissions go through a Google-account-gated vulnerability submission form linked from the program page; the page states the security team replies within a couple of working days and that reward amount and severity are decided case by case. security_txt: false security_txt_note: >- https://upstox.com/.well-known/security.txt returned HTTP 403 (an origin object-store AccessDenied XML body, not an RFC 9116 document) — Upstox publishes no security.txt on any of its hosts. severity_levels: - level: critical examples: - Pre-authentication reflected or DOM XSS - Stored XSS generally accessible by users - Command injection - Deserialization attacks - Forced browsing with supplied credentials or session tokens of logged-in users - SQL injection - Forced browsing leading directly to customer data - Account takeover through logic flaw or inappropriate session handling - level: high examples: - Post-authentication reflected or DOM XSS - CSRF involving purchases, sales or funds transfers - OTP bypass - Logic flaws allowing manipulation of data - Directory browsing enabling bulk sensitive data download - Session fixation - Logic flaws resulting in potential privilege escalation - level: medium examples: - Directory browsing enabling isolated data download - Logic flaws causing data integrity issues without privilege escalation - level: low examples: - Account enumeration where rate limiting is not enforced - Logic flaws with no privilege escalation or data integrity impact - level: informational examples: - Directory browsing with no critical files available - Disclosure of non-critical business information - Internal asset enumeration or disclosure out_of_scope: - Content Security Policy not deployed - Text injection - CSRF (except the cases listed under high), CORS, HSTS - HttpOnly flag not set on cookies - Outdated software with no public exploit or not exploitable in the current configuration - Missing SPF, DKIM and DMARC records - Missing HTTP security headers that do not lead to an exploitable condition - DoS / DDoS - UAT and DEV environments - Session expiration - Rate limiting - Origin IP disclosure - EXIF data - The bug bounty form and its services - Clickjacking / X-Frame-Options - Phishing-based attacks in_scope_domains: - smallcases.upstox.com - streak.upstox.com - community.upstox.com - upstox.com/uplearn - learn-lms.upstox.com - help.upstox.com - employee-benefits.upstox.com - webstories.upstox.com disclosure_rules: - Researchers must keep findings confidential and must not disclose publicly or to other organizations. - No copying, sharing, transferring or replicating of customer data. - Testing must not affect any commercial or trading service at Upstox. - No social engineering of Upstox customers or staff. - Findings must be from the latest stable version, new, reproducible and remotely exploitable in a standard configuration. evidence: - source: https://upstox.com/bug-bounty/ http_status: 200 kind: bug bounty program page (live fetch) - source: https://upstox.com/trust-security/ http_status: 200 kind: responsible disclosure section linking the bug bounty program - source: https://upstox.com/.well-known/security.txt http_status: 403 kind: security.txt probe (absent)