Legal

Responsible Disclosure Policy

Last updated: January 1, 2025

TL;DR — We welcome responsible security research

If you find a vulnerability in BugBounty's own infrastructure, tell us before going public. We will investigate, fix, and acknowledge your contribution. We will not take legal action against researchers who act in good faith.

Scope

This policy applies to security vulnerabilities found in:

  • The BugBounty web application (app.bugbounty.example)
  • The BugBounty API (api.bugbounty.example)
  • Authentication, session management, and account security
  • Access control and authorization logic
  • Data handling and storage

Out of scope: Social engineering attacks against our staff, physical attacks, denial-of-service, and vulnerabilities in third-party services we use (report those to the respective vendor).

Our Commitments to You

  • Safe harbour: We will not pursue civil or criminal action against researchers who discover and report vulnerabilities in good faith and in compliance with this policy.
  • Timely response: We will acknowledge receipt of your report within 3 business days and provide a status update within 10 business days.
  • Transparency: We will keep you informed of our progress as we investigate and resolve the issue.
  • Credit: With your permission, we will publicly acknowledge your contribution once the vulnerability is resolved.
  • Coordination: We ask for a 90-day coordinated disclosure window before you publish details publicly. We will work to remediate within that window.

Your Commitments to Us

To qualify for safe harbour, we ask that you:

  • Make a good-faith effort to avoid privacy violations, data destruction, service interruption, and harm to other users.
  • Only interact with accounts you own or have explicit permission to test.
  • Do not exfiltrate, modify, or destroy any data. Stop as soon as you have confirmed the vulnerability.
  • Do not perform denial-of-service attacks or automated scanning that degrades service quality.
  • Report the vulnerability promptly and provide us a reasonable period to remediate before any public disclosure.

How to Report

Submit your finding through the BugBounty platform itself — create an account, find the BugBounty Internal Security program, and submit a report with the following information:

  • A clear description of the vulnerability and its potential impact
  • Step-by-step reproduction instructions
  • Affected URLs, parameters, or components
  • Screenshots or video proof-of-concept (where applicable)
  • Your assessment of severity (CVSS score if possible)

Please encrypt sensitive details using our PGP key if the vulnerability involves credentials or personal data — contact us for the key.

Severity and Rewards

SeverityExamplesReward
CriticalRCE, auth bypass, mass data leakUp to 5,000 cr
HighIDOR, SQLi, account takeoverUp to 2,500 cr
MediumStored XSS, CSRF, privilege escalationUp to 1,000 cr
LowSelf-XSS, info leak, missing headersUp to 250 cr

Rewards are paid in Platform credits. Final amounts are determined by the security team after triage and may vary based on impact and quality of the report.

Hall of Fame

Researchers who have responsibly disclosed valid vulnerabilities will be listed in our public Hall of Fame (with their consent). We believe in recognising the security community's contributions to making the Platform safer for everyone.