Tide Logo
Tide Logo


Responsible Disclosure

Tide believes in keeping its members data secure and private. We acknowledge the valuable role that independent security researchers play in security and, as a result, we encourage responsible reporting of any vulnerabilities that may be found in our site or product. Tide welcomes feedback from the security community on its product, platform and website to help keep our business and members safe. If you have information related to security vulnerabilities discovered within Tide products and services, please submit a report in accordance with our Responsible Disclosure Policy.

Responsible Disclosure Policy

Our Responsible Disclosure Policy allows for security testing to be conducted by anyone in the security community with safe communication of those results. If any vulnerabilities are identified please report them to Tide using the contact details mentioned at https://www.tide.co/.well-known/security.txt.

We welcome your support to help us address any security issues, both to improve our products and protect our members.

What we would like to see from you:

Your reports will be reviewed and validated by a member of the Tide Security team. Providing clear and concise steps to reproduce the issue will help to expedite the response. As a minimum, your report must include:

  • Clear description and evidence of the vulnerability (logs, screenshots, responses)

  • Any platforms, operating systems, versions that are relevant

  • Any relevant IP addresses, URLs and parameters

  • Any supporting evidence you have collected (logging, tracing etc.)

  • Your name, contact details and other personal details on our request

  • Please preserve as much evidence as possible.

  • Describe the impact. How would the vulnerability be exploited?

  • Steps to reliably reproduce the issue.

Test Plan

If you are legally resident in a country in which Tide offers business accounts and meet the necessary criteria for an account in that region you may sign up for an account. Once your request for an account is approved via our normal “Know Your Customer” (KYC) processes you may use this account to perform exploratory testing of all API’s listed in the programme scope below. If your request for an account is denied for any reason we are not able to facilitate testing accounts but you may still perform unauthenticated testing on any public API’s or applications listed in the programme scope.

We would consider being able to create an account without going through our KYC processes to be a critical severity issue.

Identifying Yourself

It is likely that traffic generated by researchers will be categorised as malicious. Identifying your traffic will help us classify the traffic accordingly. We request that this is done by adding the following header to your request:

SecurityResearcher: <Name/Handle>

In Scope

  • Domain

    • web.tide.co

    • api.tide.co

    • login.tide.co

    • app.tide.co

    • api.tideplatform.in

    • www.tide.co

  • Android: Play Store: com.tideplatform.banking

  • Android: Play Store: co.tide.tideplatform.in

  • iOS: App Store: co.tide

Out of Scope

  • Domains

    • account-reader.tide.co

    • community.tide.co

    • status.tide.co

    • admin.tide.co

    • *-wip.tide.co

    • *-staging.tide.co

    • www.tidecharity.org.uk

    • portaldesign.tide.co

    • s.tide.co

    • memberconnect.tide.co

    • professionals.tide.co

    • *.stg-tideplatform.in

    • *.wip-tideplatform.in

Out of scope vulnerabilities

When reporting vulnerabilities, please consider both the attack scenario/exploitability and the impact of the vulnerability. The following issues are considered out of scope:

  • Reports from automated tools or scans

  • Do not try to exploit service providers we use, prohibited actions include, but are not limited to brute-forcing login credentials of Domain Registrars, DNS Hosting Companies, Email Providers and/or others.

  • Reports affecting outdated browsers

  • Denial of Service Attacks

  • Content spoofing and text injection issues without showing an attackvector/without being able to modify HTML/CSS

  • Missing best practices in Content Security Policy.

  • Issues without clearly identified security impact or speculative theoretical exploitability

  • Missing security best practices and controls (rate-limiting/throttling, lack of CSRF protection, lack of security headers, missing flags on cookies, descriptive errors, server/technology disclosure - without clear and working exploit)

  • Lack of crossdomain.xml, p3p.xml, robots.txt or any other policy files and/or wildcard presence/misconfigurations in these.

  • Use of known vulnerable libraries or frameworks without a clear and working exploit

  • Self-exploitation (cookie reuse, self cookie-bomb, self denial-of-service etc.)

  • Self Cross-site Scripting vulnerabilities without evidence on how the vulnerability can be used to attack another user

  • Lack of HTTPS

  • Reports about insecure SSL / TLS configuration

  • Password complexity requirements, account/email enumeration, or any report that discusses how you can learn whether a given username or email address has a Tide related account

  • Presence/Lack of autocomplete attribute on web forms/password managers.

  • Server Banner Disclosure/Technology used Disclosure

  • Full Path Disclosure

  • IP Address Disclosure

  • CSRF on logout or insignificant functionalities

  • Lack of Secure or HTTP only flag on non-sensitive cookies

  • Publicly accessible login panels

  • Clickjacking

  • CSS Injection attacks. (Unless it gives you the ability to read anti-CSRF tokens or other sensitive information)

  • Tabnabbing

  • Host Header Injection (Unless it gives you access to interim proxies)

  • Cache Poisoning

  • Reflective File Download

  • Cross-Origin Resource Sharing (CORS) Access-Control-Allow-Origin: * or accepting of custom Origin header that does not specifically show a valid attack scenario

  • PRSSI - Path-relative stylesheet import vulnerabilities (without an impactful exploitation scenario - for example stealing CSRF-tokens)

  • OPTIONS/TRACE/DELETE/PUT/WEBDAV or any other HTTP Methods accepted by the server which do not specifically show a valid attack scenario

  • Cookie scoped to parent domain or anything related to the path misconfiguration and improperly scoped

  • Private IP/Hostname disclosures or real IP disclosures for services using CDN

  • Open ports that do not lead directly to a vulnerability

  • Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)

  • Lack of DNS CAA and DNS-related configurations

  • Weak Certificate Hash Algorithm

  • Social engineering of Tide employees or contractors

  • Any physical/wireless attempt against Tide property

  • Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]

  • Open redirect - unless an additional security impact can be demonstrated

  • Theoretical sub-domain takeovers with no supporting evidence

  • Any issue in a mobile application that can only be exploited on a rooted or jailbroken device

  • Reports of broken links or unclaimed social media accounts

  • Security vulnerabilities in third-party products or websites that are not under Tide’s direct control

  • Issues that require unlikely user interaction

  • Public Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis.

Safe Harbor

If you conduct your security research and vulnerability disclosure activities in accordance with this policy, Tide will consider your research to be authorized. We will not initiate legal action against you, nor will we ask law enforcement to investigate you, provided you act in good faith and avoid any privacy violations, destruction of data, or interruption of our services.

Recognition & Leaderboard

We want to celebrate the contributions of the security community. Researchers who submit a validated, unique, and in-scope vulnerability will be eligible for:

  • Leaderboard Points: Awarded based on the CVSS severity, real life impact, articulation and responsiveness to any questions.

  • Public Attribution: Your alias listed on our public leaderboard.

The leaderboard is available at - https://www.tide.co/responsible-disclosure/leaderboard/

Confidentiality & Disclosure

To protect our members, we require that you keep all information about a discovered vulnerability confidential until Tide has formally closed the report and granted explicit permission for public disclosure. Coordinated Disclosure is a requirement for leaderboard eligibility; "leaking" details or failing to give Tide a reasonable time to remediate will result in a permanent ban from the program.

Our Commitment to You

When you report a vulnerability to Tide, we commit to the following:

  • Initial Acknowledgment: Within 3 business days of submission.

  • Triage & Validation: Within 10 business days.

  • Status Updates: We will notify you when a fix is deployed or if we require more information.

Tide | Do what you love.
Tide Platform Limited (Tide) designs and operates the Tide website and app. Tide is not a bank. Tide is authorised by the Financial Conduct Authority (FCA) under the Electronic Money Regulations 2011 under firm reference number 900843 for the issuing of electronic money and the provision of payment initiation services and account information services under the Payment Services Regulations 2017. Tide is also authorised and regulated by the Financial Conduct Authority in relation to its credit and insurance broking activities (firm reference 718743). Tide is incorporated and registered in England and Wales with company number 09595646 and registered office at 4th Floor The Featherstone Building, 66 City Road, London, EC1Y 2AL. Tide offers bank accounts powered by ClearBank® Ltd (ClearBank) (account sort code is 04-06-05). ClearBank is authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and the Prudential Regulation Authority under registration number 754568. Eligible deposits with ClearBank are protected up to a total of £120,000 by the Financial Services Compensation Scheme (FSCS), the UK's deposit guarantee scheme. For further information visit Home. ClearBank Ltd is authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and the Prudential Regulation Authority (Financial Services Register number: 754568). Registered Address: ClearBank, Level 27, The Broadgate Tower, 20 Primrose Street, London, United Kingdom, EC2A 2EW. Eligible deposits held in the Tide Business Current Account (powered by ClearBank) are covered by the Financial Services Compensation Scheme (“FSCS”) subject to eligibility. All eligible deposits at the same bank are aggregated to determine the coverage level for each depositor up to £120,000, therefore if you have any other product/services with ClearBank these will be aggregated. To find out more and to check your eligibility please visit: About us . Some of Tide’s members also hold e-money accounts powered by PrePay Technologies Limited (PPT) (account sort code is 23-69-72). PPT is an electronic money institution authorised by the FCA under the Electronic Money Regulations 2011 under firm reference number 900010 for the issuing of electronic money. PPT holds an amount equivalent to the money in Tide current accounts in a safeguarding account which gives members protection against PPT’ insolvency. Tide Cards may be issued by both Tide and PPT, who are licensed by Mastercard International for the issuance of cards. The issuer of your Tide card will be identified on your monthly card statement. Tide Capital Limited is an appointed representative of P1 Investment Services Limited which is authorised and regulated by the Financial Conduct Authority under firm reference number 752005 to carry out such regulated activities as are involved in the provision of Tide Investment Account. Seccl Custody Limited is the custodian of assets held in Tide Investment Account and is authorised and regulated by the Financial Conduct Authority (firm reference number 793200) and registered in England and Wales under No. 10430958. Registered office 20 Manvers Street, Bath BA1 1JW. Tide, the Tide logo, the Swell, and Do Less Banking are trademarks and trade names of Tide Platform Limited, and may not be used or reproduced without the consent of the owner.