Bug Bounty Reports
Use this form to submit bug reports for the Alias Payment bug bounty program.
Make sure you read and understand the rules of the program. You can read more at
Your report will be acknowledged within 24 hours, and you’ll receive a more detailed response within 48 hours indicating the next steps in handling your report.
After the initial reply to your report, the security team will endeavor to keep you informed of the progress being made towards a fix and full announcement. These updates will be sent at least every five days. In reality, this is more likely to be every 24-48 hours.
If you have not received a reply to your email within 48 hours, or have not heard from the security team for the past five days, there are a few steps you can take:
- Contact the current security coordinator directly: Giovanni Collazo (hello[at]
- Contact our support team on
- Send a message or DM on Twitter to
If you have any suggestions to improve this policy, please send a message via
Your Full Name or Pseudonym
Other apps, domains or subdomains not listed below and 3rd party services, are not in scope and will not qualify for a bounty. Refer to the bug bounty website for in scope targets.
Gasolina Móvil iOS Mobile App
Gasolina Móvil Android Mobile App
For the initial prioritization and rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. You can find more info at
P1 - Critical
P2 - Severe
P3 - Moderate
P4 - Low
Summary of the Vulnerability
A one sentence description of the found vulnerability.
Steps to Reproduce the Bug
In order to accept this bug our team has to be able to reproduce the bug. Please provide step by step instructions on how to reproduce and confirm the bug.
Real World Scenario
Explain how the attack could be executed in a real world scenario to compromise user accounts or data
Additional Comments or Links
Include any additional comments or links to videos or any other resource you think might help evaluate your submission
A copy of your responses will be emailed to the address you provided.
Never submit passwords through Google Forms.
This form was created inside of Alias Payments.