Square , which specializes in the mobile payments industry, is launching its own bug bounty program, encouraging researchers to look for errors in the payments system the company has developed.
Square's service allows merchants, shopkeepers, taxi drivers, and anyone else with a smartphoneto accept credit and debit cards through the use of a small device that connects to the phone.
The security of transactions is a primary goal for the company.
“We monitor every transaction, innovate in fraud prevention, and comply with top standards for managing our network and the security of web and client applications”, wrote the head of the company's security department, Neal Harris, in a blog post.
“Today, we are very excited to announce our new bug bounty program, in collaboration with HackerOne. We recognize the significant contribution that the researcher community can provide in finding bugs, and we ask for your help”.
Vulnerability reporting will be carried out through the HackerOne platform, which facilitates and simplifies the process.
The website provides detailed information about which bugs are rewarded by the company, what information must be sent to Square's security team, as well as the notification policy that must be followed for the payment of the cash reward. So far, the minimum reward for finding vulnerabilities has been set at $250 / €187.

