Bug Bounty Program

Let’s make technology safer, together.

Bug Bounty Program

  • Let’s make technology safer, together.


  • At Oen Tech we believe technology should serve people—securely and reliably.

  • To protect our users’ privacy and transaction security, we invite the global security community to stand with us: find and fix potential risks so our products become stronger and safer.

  • Every vulnerability you discover is a chance for us to improve.

Why participate?

  • Cash rewards for every valid, eligible report
  • Your research may safeguard tens of thousands of users
  • We value every reporter and will credit you publicly (with your consent)
  • Become a driving force in building one of Asia’s leading security cultures at Oen Tech

How to join?

If you are an ethical security researcher, developer or engineer, you’re welcome. Read and follow our Responsible Disclosure Policy, then submit bugs via:
Report form:
Your report should include
  • Issue description & reproduction steps (URLs, screenshots, PoC, etc.)
  • Impact scope (user data, funds, service disruption, etc.)
  • Test environment & device info (OS, browser, app version)

Vulnerabilities we care about

  • Privilege escalation, account impersonation, auth-bypass flaws
  • Data leakage or improper protection of sensitive info
  • API security issues (IDOR, unauthorized access, etc.)
  • Business-logic errors in the payment flow
  • Web / App bugs (XSS, CSRF, SQLi, …)
  • Payment or collection-flow security design issues

In-scope assets

This policy covers, but is not limited to:
  • Oen Web Frontend & Merchant Dashboard
  • oen.tw official website
  • API Gateway (authorized testing only)
  • Mobile payment functions (use test merchant accounts where possible)
If in doubt, ask us first.

Reward guidelines (CVSS-based)

  • We assess severity, report quality, and reproducibility.
  • Providing a PoC, demo video, or remediation suggestion will boost the reward.
SeverityCVSS RangeBounty Range(TWD)
Critical9.0–10.0$30,000–$100,000
High7.0–8.9$10,000–$30,000
Medium4.0–6.9$3,000–$10,000
Low0.1–3.9$500–$3,000

Reports we do not accept

  • DoS / DDoS tests
  • Social-engineering / phishing
  • Testing other users’ accounts / third-party systems
  • UI bugs with no security impact
  • Scanner output that hasn’t been validated

Process & timeline

  • Submit report
  • We reply within five (5) business days
  • If valid, we start remediation and keep you updated
  • After the fix, we evaluate and pay the bounty
  • With your permission, you’ll be added to the Oen Tech Hall of Fame

Recognition

  • Every six months we publish a Top Contributors list on our website to honour your work (anonymous option available).
  • Feel free to mention this program on your resume, blog or social channels.

Oen Tech Responsible Disclosure Policy

Oen Tech is committed to secure, reliable products and transparent collaboration.
  • No legal action against good-faith researchers who follow this policy.
  • We respond with transparency and respect.
  • Fair rewards based on severity and report quality.
  • After remediation, you’re welcome to publish your research—we’ll gladly credit you.
Please do not:
  • Launch DDoS attacks, spam or excessive requests causing outages.
  • Use social engineering, phishing or insider attacks.
  • Access, modify, download or delete data/funds that are not yours.
  • Test non-public environments (staging, dev) without permission.
  • Publicly disclose a bug before we give explicit consent.

Let’s empower technology together.

Oen Tech is a Taiwan-based FinTech company; our product “Oen Tap&Go Pay” is changing how tens of thousands of merchants accept payments. We know trust is built on security.
We see every security researcher as a partner. Your discoveries are vital contributions to a safer financial ecosystem.
Thank you for your support and for joining us on this journey.
Questions? Contact info@oen.tw

Last modified date: July 16, 2025