Identify a security vulnerability within FYERS trading platform or FYERS App and report it to us. Read Terms & Conditions properly before reporting.
The FYERS Bug Bounty Program is open to individuals aged 18 and above.
This program exclusively covers vulnerabilities in FYERS-owned, FYERS-operated, and FYERS-maintained online trading systems (Web & Mobile) and explicitly listed in-scope assets.
Only assets where FYERS has full technical control (source code, infrastructure, deployment pipeline) are eligible for bounty consideration.
Vulnerabilities in the following are strictly out-of-scope and not eligible for bounty:
The following are not considered security vulnerabilities:
FYERS follows a first-valid-report policy:
To ensure every submission receives an appropriate technical review, FYERS follows a structured triage process.
Rewards are determined solely at FYERS' discretion based on severity, impact, exploitability, compensating controls, and regulatory risk.
Reward Bands:
Upto ₹1,00,000
Upto ₹50,000
Upto ₹20,000
Upto ₹5,000
Payout Terms:
FYERS reserves the right to withhold or modify rewards for any reason including insufficient impact, inability to reproduce, or policy violation.
Once a submission is accepted and FYERS requests an invoice, the researcher must submit the invoice within 15 days. Invoices not submitted within this period will result in the bounty being forfeited, and the submission will be closed with no payout.
Participants must:
Violation may result in disqualification, banning from the program, or legal action.
Additionally, the following actions will result in immediate disqualification and potential legal escalation:
Participants must:
FYERS provides no "safe harbor" protections for activity deemed unlawful under Indian law.
FYERS is not responsible for any damages resulting from participation.
Participants agree to indemnify FYERS against claims arising from violation of these terms.
Acceptance, validation, or reward of a submission does not constitute admission of legal liability, regulatory breach, or systemic failure by FYERS.
Severity classification and bounty determination are internal risk assessments and do not imply regulatory non-compliance.
FYERS reserves the right to reject any submission, including but not limited to:
All decisions on eligibility, severity, and payout are final.
FYERS may modify, pause, or terminate the bug bounty program at any time without notice.
These terms are governed by the Laws of India. Courts of Bengaluru Urban shall have exclusive jurisdiction.
For general queries about the FYERS Bug Bounty Program, please reach out to:
email_emoji [email protected]
All vulnerability submissions must be made exclusively through the official submission form to ensure proper triage, tracking, and compliance:
form_url_emoji Submit Vulnerability via Zoho Form
Submissions sent through email, social media, or other channels will not be considered valid for bounty evaluation.
Severity determination is made solely by FYERS based on this rubric and is not subject to negotiation. FYERS may reference CVSS scoring; however, final severity is determined based on trading-system context and regulatory exposure rather than CVSS score alone.
Additionally, the following conditions automatically reduce severity:
General Principles
All submissions are independently assessed based on exploitability, demonstrated security impact, reproducibility, affected asset scope, and compliance with the FYERS Bug Bounty Program. Examples below are illustrative and not exhaustive. Inclusion of an example under a severity category does not automatically qualify a submission for a bounty.
Theoretical attack chains, speculative impacts, or findings requiring prior compromise of credentials, authenticated sessions, phishing, malware, social engineering, or another independent vulnerability will not be used to increase the severity of a report.
Definition
A demonstrated vulnerability resulting in practical compromise of customer accounts, trading operations, regulated customer data, or FYERS backend infrastructure.
Critical findings must be independently reproducible and must not rely on phishing, social engineering, prior credential compromise, malware, or victim interaction.
Examples
Account Takeover
Unauthorized Trading
Regulated Customer Data
Financial Impact
Platform Availability
Mass User Impact
Infrastructure
Definition
Validated vulnerabilities affecting a single user that result in meaningful confidentiality, integrity or availability impact.
The impact must be practically demonstrated.
Examples
Sensitive Information Disclosure
Availability
Access Control
Business Logic
Authenticated Client-Side Code Execution
Definition
Validated vulnerabilities requiring additional conditions or having limited customer impact.
Examples
Authorization
Token Issues
Client-Side Injection
Business Logic
Publishable Keys
Definition
Validated security weaknesses with limited practical security impact.
Examples
Definition
Observations, defence-in-depth recommendations, product improvements or deviations from security best practices that do not demonstrate an exploitable security impact.
These may be tracked internally but are not eligible for bounty.
Product Behaviour
Security Hardening
Non-sensitive Information Disclosure
Legacy Assets
Rate Limiting
Mobile Findings
The following are not considered security vulnerabilities under the FYERS Bug Bounty Program.
Expected Behaviour
Findings Requiring Independent Compromise
Reports where impact depends on:
Functional Defects
Unsupported Impact Claims