vulns.co
/
GKData.io MCP

TrueLayer · 2 min read

TrueLayer Vulnerability Disclosure Program

TrueLayer · Intigriti. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Disclosure needs written consent. Automation is bounded; disruption, social engineering, physical intrusion and brute force are prohibited.

Eligibility and submission status

Researcher-identified platform accounts are required. Certain production access requires customer identity checks; credentials for the associated payment-service portfolio are unavailable. Platform eligibility requires age 18, or 16 with guardian permission, plus legal and employer authorization.

Logged-out policy and login invitation do not independently establish current intake status.

Advertised rewards

No monetary bounty schedule; currency and numeric bounds remain null.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 11 published rows
AssetTypeGroup / eligibility
*.truelayer.comWildcardTier 1
*.zimpler.netWildcardTier 2
*.sandbox.zimpler.netWildcardTier 3
*.staging.zimpler.netWildcardTier 3
*.truelayer-sandbox.comWildcardTier 3
checkout-playground.zimpler.comPublished location: http://checkout-playground.zimpler.comURLTier 3
devdocs.zimpler.comPublished location: http://devdocs.zimpler.comURLTier 3
identify.zimpler.comPublished location: http://identify.zimpler.comURLTier 3
okta-oauth2.zimpler.comPublished location: http://okta-oauth2.zimpler.comURLTier 3
swish-playground.zimpler.comPublished location: http://swish-playground.zimpler.comURLTier 3
zimpler-merchant.zimpler.comPublished location: http://zimpler-merchant.zimpler.comURLTier 3
Out of scope · 1 published rows
AssetTypeGroup / eligibility
*.zimpler.comWildcard

Review limitations

  • The separate paid program does not change this VDP’s explicit no-reward policy.
  • Anonymous-reporting language coexists with platform-account requirements; anonymous intake was not verified.
  • No revision archive, expanded safe-harbor text or complete incorporated-document review was established.
  • Logged-out review; summaries omit inventories and procedures. Live terms prevail; this record grants no authorization.

Sources and provenance

  1. TrueLayer Vulnerability Disclosure Program policy TrueLayer / Intigriti · reviewed 2026-10-03
  2. Intigriti Researcher Terms & Conditions Intigriti · reviewed 2026-10-03
  3. Published Intigriti asset table TrueLayer · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software