BalmyTrip
loginSign In
Community & Security

Bug Bounty & Customer Feedback

Last updated: July 16, 2026

workspace_premium

Track your earned BalmyBits in the Rewards Hub

View your balance, referral tier, and redemption history →

At BalmyTrip, our community drives everything we do. Whether you are an everyday traveler wanting to help us improve our UI/UX booking experience, or a security researcher responsibly disclosing a vulnerability—we want to hear from you.

rate_reviewPlatform UI/UX Feedback

lightbulb

Your feedback helps us improve

We listen to our customers to make BalmyTrip the best travel platform in the world. Just because we have a high satisfaction rating doesn't mean we've stopped improving—your genuine thoughts help us get there.

redeem

Help Us Improve & Get Rewarded! New

If your genuine assessment helps us identify a critical area for UI/UX improvement through our internal research, we will reward you with 100 BalmyBits (= ₹100) as a token of our appreciation.

We want your honest, unfiltered assessment. What genuinely works well for you? Where did we fall short?

0/50 characters minimum

bug_reportBug Bounty Programme

The security of our customers and their travel data is our highest priority. We believe that collaborating with the global security research community is a crucial part of maintaining a secure platform. This Bug Bounty Programme outlines our rules of engagement, scope, and reward tiers for responsibly disclosing security vulnerabilities.

Before You Submit a Report

grade
Quality Over Quantity

We process reports faster when they are crystal clear. Providing exact reproduction steps, a solid proof-of-concept, and a realistic impact assessment ensures rapid triage. Exceptional reports that clearly demonstrate a threat to our travelers' data or booking infrastructure are prioritized and compensated accordingly.

terminal
Hunt for Novel Threats

We aren't looking for automated scanner noise. We want you to dig deep into our custom business logic, pricing engines, and booking flows. Uncovering unique, previously unknown flaws that directly impact our platform's integrity will earn you the highest tier of rewards and recognition.

verified_user
Report Privately, Fix Collaboratively

Trust is a two-way street. We ask that you submit your findings to us securely and refrain from publishing details until we have fully patched the issue. This collaborative approach ensures our travelers remain safe while we work diligently to resolve the vulnerability.

campaign
Do No Harm to Travelers

Your research must never disrupt the BalmyTrip experience. You are strictly forbidden from altering live itineraries, extracting real user data, or executing denial-of-service attacks. Ethical hacking means securing the platform without jeopardizing our community.

1. RULES OF ENGAGEMENT

We ask that all researchers adhere to the following principles when interacting with our systems:

  • No Automated Scanners: Do not use heavy automated scanning tools (e.g., Burp Active Scan with high threads) that could degrade platform performance or cause a Denial of Service (DoS).
  • Proof of Concept Limits: Limit your PoCs to demonstrating the flaw. Do not extract large amounts of data, pivot into internal networks, or escalate privileges beyond what is necessary to prove the vulnerability.
  • Do not access, modify, delete, or exfiltrate customer data. If you inadvertently encounter user data, halt testing and report it immediately.
  • Use your own test accounts for all security research. Do not attempt to compromise accounts belonging to other users.
  • Social engineering (e.g., phishing) of BalmyTrip employees, contractors, or customers is strictly prohibited.
  • Physical security attacks against BalmyTrip offices or data centers are strictly prohibited.

2. IN-SCOPE ASSETS

The following assets are considered in-scope for this programme:

  • *.balmytrip.com - Main web application and subdomains
  • api.balmytrip.com - Core API endpoints

Note: Third-party services, vendors, and integrations (e.g., Amadeus, Stripe) are explicitly out of scope.

3. HIGH-PRIORITY VULNERABILITIES

We are particularly interested in critical flaws that directly impact our business and customers. High-priority areas include:

  • Business Logic Flaws: Manipulating pricing, bypassing the SplitPrice feature, or booking under another user's context.
  • Authentication & Authorization: Account Takeover (ATO), bypassing Two-Factor Authentication, session hijacking, or privilege escalation.
  • Data Exposure: Unauthorized access to PII (Personally Identifiable Information) such as passport details, booking itineraries, or payment metadata.
  • Injection Flaws: SQL Injection, NoSQL Injection, Server-Side Request Forgery (SSRF), and Remote Code Execution (RCE) on the core API.

4. NON-QUALIFYING VULNERABILITIES (OUT OF SCOPE)

To ensure our team can focus on critical issues, the following vulnerabilities do not qualify for a reward unless they lead to a chained, highly impactful exploit:

  • Missing security headers or flags (e.g., missing HTTP Strict-Transport-Security, X-Frame-Options) without a demonstrable exploit.
  • Email spoofing (SPF, DKIM, DMARC misconfigurations) without demonstrable impact.
  • Clickjacking on pages lacking sensitive state-changing actions.
  • Rate limiting or brute-force issues on non-authentication endpoints.
  • Vulnerabilities requiring highly unlikely user interaction, root/jailbroken mobile devices, or physical access to a victim's machine.
  • Self-XSS (XSS that can only be triggered by the user themselves).

5. REWARD MATRIX

As a growing startup, we deeply appreciate the security community's support. While our budget is minimal, we ensure every valid report is rewarded. Rewards are issued as INR payout OR BalmyBits credit (reporter's choice).

warningP1 - Critical

Remote Code Execution (RCE), SQL Injection (SQLi), severe data leaks.

₹5,000 or 5,000 BalmyBits

gpp_badP2 - High

Stored XSS, Significant Privilege Escalation, Authentication Bypass.

₹3,500 or 3,500 BalmyBits

privacy_tipP3 - Medium

Reflected XSS, CSRF on sensitive actions, Insecure Direct Object References.

₹2,000 or 2,000 BalmyBits

infoP4 - Low

Minor misconfigurations, Information Disclosure without sensitive data.

₹500 or 500 BalmyBits

military_tech

BalmyTrip Security Hall of Fame

If your bug report is exceptionally critical to our business, or if you consistently provide high-quality reports that protect our users, we will immortalize your contributions in our Security Hall of Fame. We love giving public credit and references to researchers who truly make a difference.

6. HOW TO REPORT

If you believe you have found a security vulnerability in an in-scope asset, please submit a detailed report to cybersecurity@balmytrip.com.

Your report must include:

  • A clear description of the vulnerability and its potential impact.
  • Detailed, step-by-step instructions to reproduce the issue.
  • Proof of Concept (PoC) such as screenshots, videos, or scripts.

We aim to acknowledge receipt of your report within 48 hours and provide an initial assessment within 5 business days.

7. SAFE HARBOR

BalmyTrip considers security research conducted in accordance with this policy to be authorized. We will not initiate or support legal action against researchers for accidental, good-faith violations of this policy. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.