Skip to content
This repository has been archived by the owner on Nov 20, 2023. It is now read-only.

Commit

Permalink
Merge pull request #1171 from Hacker0x01/september-updates
Browse files Browse the repository at this point in the history
Payouts updates
  • Loading branch information
jessiwright authored Sep 28, 2023
2 parents 76817e2 + 80b471f commit cfb49a2
Show file tree
Hide file tree
Showing 2 changed files with 35 additions and 23 deletions.
56 changes: 34 additions & 22 deletions docs/hackers/payout-methods.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,32 +25,44 @@ Payout Method | Processing Time | Description
------------- | --------------- | -----------
PayPal | Monday to Friday at 11:30pm UTC | Payout time is 1-2 days.<br>As soon as the payment is initiated, you'll receive your award instantly, given that your PayPal account is set up to properly receive the amount of money HackerOne is trying to send.</br>
Bitcoin via Coinbase | Every day at 11pm UTC | Payout time is 1-2 days.<br>As soon as the payment is processed, you'll receive your award instantly.</br>
Bank Transfer (Currencycloud) | Monday to Friday at 9am UTC | Payout time is 1-10 days.<br>You can choose between using Normal (local) or Priority (SWIFT) payments. How fast you receive your payout depends on the type of payment you're using as well as your bank. There are cases where hackers have received payments on the same day and cases where hackers have had to wait the full 10 business days. Bank transfers can be done in your own local currency. To convert bounties to your local currency, the mid-market rate is used to convert money. This saves you up to 5% compared to relying on your bank to convert the money to your local currency.</br><br>Make sure your bank isn’t on the sanctions list. Go to https://sanctionssearch.ofac.treas.gov/ to check if your bank is on the list. Banks on this list don’t qualify for bank transfers. Examples include VTB and SBERBANK.</br><br>**Note:** $10k is the maximum amount that can be processed in 1 payment. So if you're receiving a $30k bounty, you'll receive it in 3 transactions with $10k in each transaction.
Bank Transfer (Currencycloud) | Monday to Friday at 9am UTC | Payout time is 1-10 days.<br>You can choose between using Normal (local) or Priority (SWIFT) payments. How fast you receive your payout depends on the type of payment you're using as well as your bank. There are cases where hackers have received payments on the same day and cases where hackers have had to wait the full 10 business days. Bank transfers can be done in your own local currency. To convert bounties to your local currency, the mid-market rate is used to convert money. This saves you up to 5% compared to relying on your bank to convert the money to your local currency.</br><br>Make sure your bank isn’t on the sanctions list. Go to https://sanctionssearch.ofac.treas.gov/ to check if your bank is on the list. Banks on this list don’t qualify for bank transfers. Examples include VTB and SBERBANK.</br><br>**Note on payment limits:** we attempt to pay the largest payment in a single transaction allowed to us by the currency exchanges. This will vary by currency and whether it is a Priority or Regular payment. See chart below for more details.

### More Info on Bank Transfers (Currencycloud)

#### Choosing between SWIFT and Local payment
_ | SWIFT | Local
-------------- | -------- | ----------
Availability | Most currencies | Fewer currencies available
Fees | Fees imposed by banks | Does not impose a bank fee
Speed | Slightly slower | Slightly faster
Maximum payment size per single transaction (USD) | Unlimited | Depending on the currency and exchange rate, from about $15,000 USD, to unlimited. Payments due that are larger than the single transaction limit will be split up into multiple transfers

When creating your bank transfer payout preference in Settings, you will automatically be guided to available options for your bank and currency.

Generally, if you are receiving small payments, using Local delivery if it’s available to you is best for both speed and minimizing fees. Note that even if your currency doesn’t support Local delivery or SWIFT, you can ask for USD to be delivered to your bank - the only caveat is that your bank will likely give you a less favorable exchange rate, and you will need to test that yourself.

#### Currency Conversions
For bank transfers, we currently support conversions to the following currencies:

Supported Currency | Currency Code | Supported Currency | Currency Code
------------------ | ------------- | ------------------ | -------------
Australian Dollar | AUD | Mexican Peso | MXN
Bahraini Dinar | BHD | New Zealand Dollar | NZD
British Pound | GBP | Norwegian Krone | NOK
Bulgarian Lev | BGN | Omani Rial | OMR
Canadian Dollar | CAD | Philippine Peso | PHP
Chinese Yuan | CNY | Polish Zloty | PLN
Croatian Kuna | HRK | Qatari Rial | QAR
Czech Koruna | CZK | Romanian New Leu | RON
Danish Krone | DKK | Saudi Riyal | SAR
Euro | EUR | Singapore Dollar | SGD
Hong Kong Dollar | HKD | South African Rand | ZAR
Hungarian Forint | HUF | Swedish Krona | SEK
Indian Rupee | INR | Swiss Franc | CHF
Indonesian Rupiah | IDR | Thai Baht | THB
Israeli New Sheqel | ILS | Turkish Lira | TRY
Japanese Yen | JPY | Ugandan Shilling | UGX
Kenyan Shilling | KES | United Arab Emirates Dirham | AED
Kuwaiti Dinar | KWD | United States Dollar | USD
Malaysian Ringgit | MYR | |
Supported Currency (Code) | SWIFT/Local Supported | Supported Currency (Code) | Currency Code
------------ | ------------ | ------------ | ---------
Australian Dollar (AUD) | SWIFT & Local | Mexican Peso (MXN) | SWIFT Only
Bahraini Dinar (BHD) | SWIFT Only | New Zealand Dollar NZD) | SWIFT Only
British Pound (GBP) | SWIFT & Local | Norwegian Krone (NOK) | SWIFT & Local
Bulgarian Lev (BGN) | SWIFT Only | Omani Rial (OMR) | SWIFT Only
Canadian Dollar (CAD) | SWIFT & Local | Philippine Peso (PHP) | SWIFT & Local
Chinese Yuan (CNY) | SWIFT Only | Polish Zloty (PLN) | SWIFT & Local
Croatian Kuna (HRK) | SWIFT & Local | Qatari Rial (QAR) | SWIFT Only
Czech Koruna (CZK) | SWIFT & Local | Romanian New Leu (RON) | SWIFT & Local
Danish Krone (DKK) | SWIFT & Local | Saudi Riyal (SAR) | SWIFT Only
Euro (EUR) | SWIFT & Local | Singapore Dollar (SGD) | SWIFT & Local | Hong Kong Dollar (HKD) | SWIFT & Local
South African Rand (ZAR) | SWIFT Only | Hungarian Forint (HUF) | SWIFT & Local
Swedish Krona (SEK) | SWIFT & Local | Indian Rupee (INR) | Local Only
Swiss Franc (CHF) | SWIFT & Local | Indonesian Rupiah (IDR) | Local Only | Thai Baht (THB) | SWIFT Only
Israeli New Sheqel (ILS) | SWIFT Only | Turkish Lira (TRY) | SWIFT Only | Japanese Yen (JPY) | SWIFT Only
Ugandan Shilling (UGX) | SWIFT Only | Kenyan Shilling (KES) | SWIFT Only | United Arab Emirates Dirham (AED) | SWIFT Only
Kuwaiti Dinar (KWD) | SWIFT Only | United States Dollar (USD) | SWIFT & Local | Malaysian Ringgit (MYR) | SWIFT & Local


Keep in mind that:
* When receiving a payout through a bank transfer, the payout must meet the minimum amount for the type of payment before it can be sent:
Expand Down
2 changes: 1 addition & 1 deletion docs/organizations/request-code-review.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ path: "/organizations/request-code-review.html"
id: "organizations/request-code-review"
---

In addition to confirming a vulnerability has been fixed by requesting a [Retest](retest.html), you can also request a code review to verify any source code updates adequately address the reported vulnerability. These are conducted by the HackerOne Code Review Community: a group of rigorously-vetted, specialized software engineers and security experts HackerOne created as part of the [acquisition of PullRequest.com](https://www.hackerone.com/press-release/hackerone-acquires-pullrequest-power-developer-first-security-testing-solutions). You can learn more about this specialized cohort of the HackerOne Community [here](https://www.pullrequest.com/reviewers/).
In addition to confirming a vulnerability has been fixed by requesting a [Retest](/retesting.html), you can also request a code review to verify any source code updates adequately address the reported vulnerability. These are conducted by the HackerOne Code Review Community: a group of rigorously-vetted, specialized software engineers and security experts HackerOne created as part of the [acquisition of PullRequest.com](https://www.hackerone.com/press-release/hackerone-acquires-pullrequest-power-developer-first-security-testing-solutions). You can learn more about this specialized cohort of the HackerOne Community [here](https://www.pullrequest.com/reviewers/).

The **Request code review** feature allows you to send a limited code snippet patch to be reviewed as generated by `git diff`.

Expand Down

0 comments on commit cfb49a2

Please sign in to comment.