Bug Bounty & Customer Feedback
Last updated: July 16, 2026
Track your earned BalmyBits in the Rewards Hub
View your balance, referral tier, and redemption history →
At BalmyTrip, our community drives everything we do. Whether you are an everyday traveler wanting to help us improve our UI/UX booking experience, or a security researcher responsibly disclosing a vulnerability—we want to hear from you.
rate_reviewPlatform UI/UX Feedback
Your feedback helps us improve
We listen to our customers to make BalmyTrip the best travel platform in the world. Just because we have a high satisfaction rating doesn't mean we've stopped improving—your genuine thoughts help us get there.
Help Us Improve & Get Rewarded! New
If your genuine assessment helps us identify a critical area for UI/UX improvement through our internal research, we will reward you with 100 BalmyBits (= ₹100) as a token of our appreciation.
We want your honest, unfiltered assessment. What genuinely works well for you? Where did we fall short?
bug_reportBug Bounty Programme
The security of our customers and their travel data is our highest priority. We believe that collaborating with the global security research community is a crucial part of maintaining a secure platform. This Bug Bounty Programme outlines our rules of engagement, scope, and reward tiers for responsibly disclosing security vulnerabilities.
Before You Submit a Report
Quality Over Quantity
We process reports faster when they are crystal clear. Providing exact reproduction steps, a solid proof-of-concept, and a realistic impact assessment ensures rapid triage. Exceptional reports that clearly demonstrate a threat to our travelers' data or booking infrastructure are prioritized and compensated accordingly.
Hunt for Novel Threats
We aren't looking for automated scanner noise. We want you to dig deep into our custom business logic, pricing engines, and booking flows. Uncovering unique, previously unknown flaws that directly impact our platform's integrity will earn you the highest tier of rewards and recognition.
Report Privately, Fix Collaboratively
Trust is a two-way street. We ask that you submit your findings to us securely and refrain from publishing details until we have fully patched the issue. This collaborative approach ensures our travelers remain safe while we work diligently to resolve the vulnerability.
Do No Harm to Travelers
Your research must never disrupt the BalmyTrip experience. You are strictly forbidden from altering live itineraries, extracting real user data, or executing denial-of-service attacks. Ethical hacking means securing the platform without jeopardizing our community.
1. RULES OF ENGAGEMENT
We ask that all researchers adhere to the following principles when interacting with our systems:
- No Automated Scanners: Do not use heavy automated scanning tools (e.g., Burp Active Scan with high threads) that could degrade platform performance or cause a Denial of Service (DoS).
- Proof of Concept Limits: Limit your PoCs to demonstrating the flaw. Do not extract large amounts of data, pivot into internal networks, or escalate privileges beyond what is necessary to prove the vulnerability.
- Do not access, modify, delete, or exfiltrate customer data. If you inadvertently encounter user data, halt testing and report it immediately.
- Use your own test accounts for all security research. Do not attempt to compromise accounts belonging to other users.
- Social engineering (e.g., phishing) of BalmyTrip employees, contractors, or customers is strictly prohibited.
- Physical security attacks against BalmyTrip offices or data centers are strictly prohibited.
2. IN-SCOPE ASSETS
The following assets are considered in-scope for this programme:
- *.balmytrip.com - Main web application and subdomains
- api.balmytrip.com - Core API endpoints
Note: Third-party services, vendors, and integrations (e.g., Amadeus, Stripe) are explicitly out of scope.
3. HIGH-PRIORITY VULNERABILITIES
We are particularly interested in critical flaws that directly impact our business and customers. High-priority areas include:
- Business Logic Flaws: Manipulating pricing, bypassing the SplitPrice feature, or booking under another user's context.
- Authentication & Authorization: Account Takeover (ATO), bypassing Two-Factor Authentication, session hijacking, or privilege escalation.
- Data Exposure: Unauthorized access to PII (Personally Identifiable Information) such as passport details, booking itineraries, or payment metadata.
- Injection Flaws: SQL Injection, NoSQL Injection, Server-Side Request Forgery (SSRF), and Remote Code Execution (RCE) on the core API.
4. NON-QUALIFYING VULNERABILITIES (OUT OF SCOPE)
To ensure our team can focus on critical issues, the following vulnerabilities do not qualify for a reward unless they lead to a chained, highly impactful exploit:
- Missing security headers or flags (e.g., missing HTTP Strict-Transport-Security, X-Frame-Options) without a demonstrable exploit.
- Email spoofing (SPF, DKIM, DMARC misconfigurations) without demonstrable impact.
- Clickjacking on pages lacking sensitive state-changing actions.
- Rate limiting or brute-force issues on non-authentication endpoints.
- Vulnerabilities requiring highly unlikely user interaction, root/jailbroken mobile devices, or physical access to a victim's machine.
- Self-XSS (XSS that can only be triggered by the user themselves).
5. REWARD MATRIX
As a growing startup, we deeply appreciate the security community's support. While our budget is minimal, we ensure every valid report is rewarded. Rewards are issued as INR payout OR BalmyBits credit (reporter's choice).
warningP1 - Critical
Remote Code Execution (RCE), SQL Injection (SQLi), severe data leaks.
₹5,000 or 5,000 BalmyBits
gpp_badP2 - High
Stored XSS, Significant Privilege Escalation, Authentication Bypass.
₹3,500 or 3,500 BalmyBits
privacy_tipP3 - Medium
Reflected XSS, CSRF on sensitive actions, Insecure Direct Object References.
₹2,000 or 2,000 BalmyBits
infoP4 - Low
Minor misconfigurations, Information Disclosure without sensitive data.
₹500 or 500 BalmyBits
BalmyTrip Security Hall of Fame
If your bug report is exceptionally critical to our business, or if you consistently provide high-quality reports that protect our users, we will immortalize your contributions in our Security Hall of Fame. We love giving public credit and references to researchers who truly make a difference.
6. HOW TO REPORT
If you believe you have found a security vulnerability in an in-scope asset, please submit a detailed report to cybersecurity@balmytrip.com.
Your report must include:
- A clear description of the vulnerability and its potential impact.
- Detailed, step-by-step instructions to reproduce the issue.
- Proof of Concept (PoC) such as screenshots, videos, or scripts.
We aim to acknowledge receipt of your report within 48 hours and provide an initial assessment within 5 business days.
7. SAFE HARBOR
BalmyTrip considers security research conducted in accordance with this policy to be authorized. We will not initiate or support legal action against researchers for accidental, good-faith violations of this policy. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.