Welcome to the Deliveroo Bugcrowd Program! No technology is perfect and Deliveroo believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We will make an effort to respond as fast as possible.
Good luck, and happy hunting!
For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
- Researchers should include the following custom request header in all of their traffic: "X-Bug-Bounty: [username]"
- Please limit your automated tooling request to max 5 requests/sec.
- The reporter must not impact any third-party customer accounts.
- The reporter must not materially impact Deliveroo operations or in any way made use of any issues discovered for any reason beyond the identification of those issues.
- The reporter must not attempt to view, modify, damage or interact in any way with any information belonging to others, and, to the extent that reporter does this inadvertently, the reporter must disclose this to Deliveroo in their report. In particular, the reporter must make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service. If the reporter encounters personal data or personal identifiable information (PII) they must contact us immediately, not proceed with access, and immediately purge any local information.
- Do not intentionally harm the experience or usefulness of the service to others, including the degradation of services through brute-force or denial of service attacks.
By engaging or participating in this bug bounty program, you agree to treat the following types of information as Deliveroo's confidential information and not divulge to any third person (except disclosure to Deliveroo through the Bugcrowd platform) any such information until disclosure is approved in writing by Deliveroo: (i) all information you receive or collect about Deliveroo and its products, or any of Deliveroo's customers during your participation in this program; and/or (ii) vulnerability report and any vulnerability.
Disclosure of Deliveroo's confidential information to any third parties before Deliveroo's approval forfeits the reward and could disqualify you from participating in this bug bounty program in the future. Please notify Deliveroo immediately upon discovery of any loss or unauthorized disclosure of confidential information.
You must notify Deliveroo immediately if you: (i) gain access to another person's accounts or data; (ii) destroy any data; or (iii) cause interruption or degradation of Deliveroo's infrastructure and services. Additionally, if you encounter personally identifiable information, customer data, or other sensitive information, please contact Deliveroo immediately, and do not retain any copies of such information.
By submitting your vulnerability report, you perpetually allow Deliveroo the unconditional ability to use, modify, create derivative work from, distribute, publish, and display information provided in your report or to have others do the same on Deliveroo's behalf, and these rights cannot be revoked.
You must comply with all applicable laws in connection with your participation in this program.
To submit a report, please fill out the form below. All submissions are processed securely.