Legal
Responsible Disclosure Policy
Last updated: January 1, 2025
TL;DR — We welcome responsible security research
If you find a vulnerability in BugBounty's own infrastructure, tell us before going public. We will investigate, fix, and acknowledge your contribution. We will not take legal action against researchers who act in good faith.
Scope
This policy applies to security vulnerabilities found in:
- The BugBounty web application (
app.bugbounty.example) - The BugBounty API (
api.bugbounty.example) - Authentication, session management, and account security
- Access control and authorization logic
- Data handling and storage
Out of scope: Social engineering attacks against our staff, physical attacks, denial-of-service, and vulnerabilities in third-party services we use (report those to the respective vendor).
Our Commitments to You
- Safe harbour: We will not pursue civil or criminal action against researchers who discover and report vulnerabilities in good faith and in compliance with this policy.
- Timely response: We will acknowledge receipt of your report within 3 business days and provide a status update within 10 business days.
- Transparency: We will keep you informed of our progress as we investigate and resolve the issue.
- Credit: With your permission, we will publicly acknowledge your contribution once the vulnerability is resolved.
- Coordination: We ask for a 90-day coordinated disclosure window before you publish details publicly. We will work to remediate within that window.
Your Commitments to Us
To qualify for safe harbour, we ask that you:
- Make a good-faith effort to avoid privacy violations, data destruction, service interruption, and harm to other users.
- Only interact with accounts you own or have explicit permission to test.
- Do not exfiltrate, modify, or destroy any data. Stop as soon as you have confirmed the vulnerability.
- Do not perform denial-of-service attacks or automated scanning that degrades service quality.
- Report the vulnerability promptly and provide us a reasonable period to remediate before any public disclosure.
How to Report
Submit your finding through the BugBounty platform itself — create an account, find the BugBounty Internal Security program, and submit a report with the following information:
- A clear description of the vulnerability and its potential impact
- Step-by-step reproduction instructions
- Affected URLs, parameters, or components
- Screenshots or video proof-of-concept (where applicable)
- Your assessment of severity (CVSS score if possible)
Please encrypt sensitive details using our PGP key if the vulnerability involves credentials or personal data — contact us for the key.
Severity and Rewards
| Severity | Examples | Reward |
|---|---|---|
| Critical | RCE, auth bypass, mass data leak | Up to 5,000 cr |
| High | IDOR, SQLi, account takeover | Up to 2,500 cr |
| Medium | Stored XSS, CSRF, privilege escalation | Up to 1,000 cr |
| Low | Self-XSS, info leak, missing headers | Up to 250 cr |
Rewards are paid in Platform credits. Final amounts are determined by the security team after triage and may vary based on impact and quality of the report.
Hall of Fame
Researchers who have responsibly disclosed valid vulnerabilities will be listed in our public Hall of Fame (with their consent). We believe in recognising the security community's contributions to making the Platform safer for everyone.