Alasco offers state of the art software for financial controlling and ESG management.
Security is very important to us and this Bug Bounty program shall help us meet highest industry standards to offer the most secure service and experience to all parties.
Maintaining uninterrupted service for our users and partners is absolutely critical. All security testing must be performed with extreme care to avoid any form of business disruption. This includes actions that could degrade performance, interrupt service availability, or affect real customers.
Researchers are expected to act responsibly at all times and prioritize the stability, integrity, and security of Alasco systems above all else. If in doubt, stop testing immediately and seek clarification through the platform’s report discussion thread before proceeding.
The below two rule sets form the core foundation of the Alasco Vulnerability Reward Program.
They are designed to protect business continuity, user data, and testing integrity.
All researchers must review and follow both rule sets before starting any testing.
Violating either may result in disqualification of reports, revocation of bounty eligibility, or, in severe cases, suspension or termination of the entire program if operational damage occurs.
Please adhere to the following rules while performing research on this program:
In addition to the Priority Zero Rules above, the following target-specific rules apply where communicated for a given scope:
Test only during approved hours
Limit all testing activities to 08:00–17:00 CET. Do not perform any scans, automation, or manual testing outside this time window unless you have explicit written approval.
Do not disrupt our business
Do not run automation, scans, or tests that could degrade performance, disrupt services, or impact real users. If your activity risks service stability, stop immediately.
Avoid heavy automation
Do not run parallelized or high-volume automated tooling unless you have prior written approval. Default behaviour should be manual or single-threaded, low-rate testing.
No public disclosure without explicit written consent
Do not share findings, screenshots, logs, or artifacts with third parties. Report exclusively through the designated vulnerability disclosure platform. Public disclosure of any vulnerability requires written consent from Alasco — no exceptions.
No altering of real data
Never change, download, or exfiltrate company data — even if you gain access to any.
Use identifiable test data
Use dummy/test accounts and data that can be distinguished from normal traffic and production data.
Follow Security Team instructions immediately
If Alasco’s Security Team requests that you pause or stop testing, comply at once. Their direction takes precedence to protect users and operations.
If in doubt — stop and ask
When unsure about impact, environment, or data, pause testing and ask in the report discussion thread before proceeding.
We are happy to thank everyone who submits valid reports which help us improve the security of Alasco GmbH, however only those that meet the following eligibility requirements may receive a monetary reward:
Reward amounts are based on:
| Scope Type | Scope Name |
|---|---|
| api | api.alasco.de |
| web_application | app.alasco.de |
| web_application | *.alasco.de |
| web_application | *.alasco.rocks |
| Scope Type | Scope Name |
|---|---|
| undefined | All other domains or subdomains not listed in the above list of 'Scopes'. |
| undefined | Please note that all non-authenticated areas of our systems are in scope for this program. This means that any vulnerability discovered in a system or service that does not require a login to access is eligible for a reward. |
| undefined | However, any vulnerability discovered in a system or service that requires a login to access is outside the scope of this program. |
| undefined | Alasco will not provide access credentials to any system, not for testing and also not for issue validation. |
| undefined | Attention: Third-party managed infrastructure (e.g. HubSpot, Salesforce, or other SaaS platforms) where Alasco has no ability to remediate vulnerabilities at the infrastructure or platform level, regardless of the subdomain. |
| web_application | www.alasco.de |
| web_application | alasco.de |
| web_application | explore.alasco.com |
| web_application | explore.alasco.de |
| web_application | www.alasco.com |
| web_application | alasco.com |
| web_application | lp.alasco.de |
| web_application | lp.alasco.com |
| web_application | support.alasco.de |
| web_application | support.alasco.com |
This program have been found on Yeswehack on 2023-02-28.
FireBounty © 2015-2026