Sign in Get started
Solutions
ComplianceDigital ForensicsAccount SecurityWebsite SecurityWeb OptimizationSEO / GEOBusiness IntelligenceUI / UXStartupsDigital TransformationWhite LabelAI Code AuditAI / MLConsulting & AdvisoryBusiness Strategy
Products
Web HostingVPS HostingSSL CertificatesSiteLock SecurityWebsite BackupEmail Spam FilterOX App Suite360 MonitoringWeebly BuilderSite BuilderSEO (Marketgoo)Account SecurityDomainsAll Products
More
NetworkSecurity AboutCareersContactRoadmapLegal
Security

Built to be unbreakable.

Money and data sit at the centre of everything we do, so security is not a feature - it is the foundation. 16+ years of operation, zero breaches, secure payments and encryption at every layer. #NeverBeenHacked.

#NeverBeenHacked Payments through internetivo 2FA enforced
Security - Internetivo
The track record

A record we protect every day.

Not a promise - a measured history of secure operation on real money and real data.

16+

years operating

EU registered, running production payments and marketplaces for over a decade and a half.

0

breaches, ever

Zero successful breaches across the entire history of the platform. #NeverBeenHacked.

2FA

enforced

Two-factor authentication is required, not optional - every account is protected by default.

What's included

How we keep you safe.

Layered defences across funds, identity, infrastructure and data - so a single failure is never enough.

Payments you can trust

You pay internetivo, and internetivo pays out only on delivery - funds are never exposed to a counterparty who has not earned them.

Encryption everywhere

Data is encrypted at rest and in transit, with secrets stored under a dedicated encryption scheme - not in plain config.

Enforced 2FA

Two-factor authentication is mandatory, with trusted-device handling so security never means friction for legitimate users.

Sanctions and country limits

We do not pay out to sanctioned countries or where our payment partners cannot operate, and our payment processor screens every card payment for fraud.

Anti-DDoS and hardening

Rate limiting, DDoS protection and failover infrastructure keep the platform online and resilient under attack.

Signed federation

Every message between nodes is cryptographically signed and verified - the network cooperates without blind trust.

Where you'll use it

Where security shows up.

The two moments that matter most: protecting your money, and what happens if something goes wrong.

Your money

internetivo protects every deal

The buyer pays Internetivo when a deal starts, and the money is only released on agreed delivery. Payments run through Stripe under PCI-DSS, so card data never touches our servers - and a dispute keeps the money safe until it is resolved.

How payments work
When it counts

Disclosure and incident response

We run a responsible-disclosure program for security researchers, monitor continuously, and have a defined incident response process. Report a vulnerability and you reach a human who acts on it.

Report a vulnerability
Why Internetivo

Why you can trust Internetivo.

Trust here is structural - backed by standards, audits and a proven history, not marketing.

Proven, not promised

16+ years and zero breaches. The security posture is battle-tested in production, not described in a whitepaper.

Aligned to standards

GDPR compliant and ISO 27032 aligned, with PCI-DSS handled via Stripe.

Independent scrutiny

Our Bug Bounty programme means approved, vetted researchers test us under an agreed scope.

Defence in depth

Payment controls, encryption, enforced 2FA, sanctions limits and signed federation stack so no single layer is a single point of failure.

FAQ

Security questions, answered.

Is my money safe?

Yes. The buyer pays internetivo, and internetivo pays out only on delivery, so neither side is exposed. Card payments are processed by Stripe under PCI-DSS - card details never touch our servers.

How is my data protected?

Data is encrypted at rest and in transit, secrets are stored under a dedicated encryption scheme, and access is gated by enforced 2FA. We are GDPR compliant and ISO 27032 aligned.

Have you ever been hacked?

No. In 16+ years of operation there has never been a successful breach. #NeverBeenHacked - and we run a responsible-disclosure program to keep it that way.

How do I report a security issue?

We run a private Bug Bounty programme. You register, apply, and once we approve you, you test within an agreed scope and submit findings through the Bug Bounty ticket channel. See our Bug Bounty programme policy for the full process.

Bug Bounty programme

Bug Bounty programme

Internetivo has been building and running online services since 2010, and we take the security of our platform and our customers seriously. We run a private, invitation-controlled Bug Bounty programme for security researchers. Because internetivo.com is a live platform serving real people, participation is by approval only: you register, apply, and are approved by us, and we grant you a scope to test before you begin. The programme page gives the overview; this section is the full policy.

How to take part

  1. Register an account on internetivo.com.
  2. Apply to the programme through the Bug Bounty channel, by opening a ticket in the Bug Bounty department. Tell us your handle and the kind of testing you do.
  3. We review your application. If we approve you, we confirm your scope and the rules for your testing in writing.
  4. Only after approval may you begin testing, and only within the scope we granted.

Testing anything without our prior approval, or outside your granted scope, is not authorised and is not covered by this programme.

Where you test

Approved researchers test against a staging copy of the platform that we name in your approval, never against internetivo.com itself. internetivo.com serves real people, real data and real money, so it is out of scope for everyone. Production testing may be offered later, by name, to researchers with a completed event and a clean track record. On staging, test only within the scope we grant you in writing and under the rules of engagement below: use only accounts you create yourself, prove an issue with a single record of your own and stop there, and never run automated scanners or anything that degrades availability.

If demonstrating an issue would require touching another person’s account, data, or money, stop there: report it with what you already have and do not prove it against anyone else’s data. One record of your own is always enough. Report it, do not prove it.

What to look for

We classify findings by real-world impact, using the rubric below. Your report proposes a severity; we confirm it. The examples are indicative, not exhaustive.

SeverityWhat qualifiesPoints
CriticalAuthentication bypass, remote code execution, mass exposure of personal data, or anything that moves money.100
HighCross-tenant data access, privilege escalation, or stored XSS in an admin view.50
MediumReflected XSS, CSRF on a state-changing action, or an IDOR on non-sensitive records.20
LowInformation disclosure with limited impact, or missing hardening headers.5
InformativeBest-practice notes, raw scanner output, or theoretical issues with no demonstrated impact.0

Points are awarded when a report is accepted, never at submission, and severity is our call against this published rubric. Specific reward amounts are confirmed when you are accepted into the programme and announced for each programme or event; see “How rewards work” below.

Out of scope and non-qualifying

The following are out of scope, and some are things you must never do:

  • Any system, domain, or environment other than the staging copy and the scope we grant you in writing, including internetivo.com itself.
  • Anything that touches money, payouts, invoices, or financial records.
  • Any other user’s or customer’s personal data, account, or content. This is a multi-tenant platform, and other people’s data is never a valid target.
  • Denial of service, load or stress testing, or anything that degrades availability.
  • Social engineering, phishing, or physical attempts against our staff, customers, or infrastructure.
  • Automated scanners, brute forcing, or high-traffic tooling.
  • Accessing, changing, or deleting data that is not yours. If you come across someone else’s data, stop immediately, do not save or share it, and tell us.
  • Third-party services we rely on (for example our payment processor, DNS, or CDN): report those directly to the vendor.
  • Non-qualifying reports: raw scanner output, theoretical issues with no demonstrated impact, best-practice suggestions, and missing hardening headers with no exploit path. We may log these as Informative.

What to do when you find something

Submit one report per issue through the official Bug Bounty channel, by opening a ticket in the Bug Bounty department. A good report includes:

  • Asset: the environment and the exact URL, endpoint, or feature affected.
  • Class and severity: the vulnerability class and the severity you claim against the rubric above.
  • Reproduction: clear, step-by-step instructions we can follow.
  • Proof: the minimum needed to demonstrate the issue. One record is enough; never exfiltrate data.
  • Impact: what an attacker could actually do with it.

What happens next: your report moves through received → triaged → accepted, duplicate, out of scope, or informative → fixed → paid. We aim to give a first response within five business days and a realistic remediation timeline after we triage. Duplicates are recorded against the original report with a timestamp, which protects both sides.

How rewards work

  • Points at acceptance. You earn points when a report is accepted and its severity confirmed, never for volume of submissions.
  • Reputation and leaderboard. Points build a public track record shown as handle and points only, never your legal name, country, or anything from your identity.
  • Tiers unlock trust. A track record earns faster triage, private scope, and, over time, a wider scope. Trust is extended gradually.
  • Paid by bank transfer. Accepted rewards are paid by bank transfer, outside the platform, after the identity and sanctions check below.
  • Identity at payout, not at the door. You report and accrue points pseudonymously (a handle and an email). Identity verification, sanctions screening, and a payout destination that matches the verified name are required only for your first payout.

The programme is growing in stages. Today it runs on reputation and event prizes; specific monetary reward amounts and any time-boxed events are announced to approved participants. We are honest about this rather than promising a payout the programme is not yet ready to make.

First event: Internetivo bug bounty weekend, 31 October to 2 November 2026 (staging only, about EUR 1,000 prize pool).

Who we can pay

Eligibility to be paid is subject to identity verification and sanctions screening at your first payout. We can pay researchers in most countries in EUR, but we cannot pay anyone located in, or a national or resident of, a country or region under sanctions or embargo, or anyone appearing on an applicable sanctions list, or where our payment partners cannot lawfully operate. Reputation and leaderboard standing are open to every valid reporter regardless of payability.

Safe harbour

For approved participants acting in good faith and within the scope we granted, we will treat your research as authorised, we will not pursue or support legal action against you for accidental, good-faith violations, and we will work with you to resolve issues quickly. This protection does not extend to testing carried out before approval, outside your granted scope, or in breach of the rules below, and it does not cover harm to other people’s data, money, or access to the service.

Rules of engagement

  • Do not test before you are approved, and stay inside the scope we grant you.
  • Use only accounts you created yourself. No accounts but your own.
  • Do not exfiltrate data. One record is enough to prove an issue; stop there.
  • Test manually and carefully. No automated scanners, no denial of service.
  • No social engineering or phishing of our staff or customers.
  • Do not disclose an issue publicly before we have fixed it and agreed the timing with you.

Coordinated disclosure

Please give us up to 90 days from your report before any public disclosure, or until a fix has shipped if that is sooner, and coordinate the timing with us. We will credit you for a valid report if you would like to be named.

Found something without being in the programme?

If you come across a security issue without being an approved participant, please do not investigate further and do not access anyone else’s data. Register an account and report it through the Bug Bounty channel, and do not disclose it publicly. We will take it from there.

Security questions? Talk to a human.

Whether you are evaluating Internetivo for your business or reporting a vulnerability, we will answer directly - no bots, no runaround.