BOUNTY ACTIVE

BUG BOUNTY
PROGRAM

Help make the web more secure. Find vulnerabilities, submit reports, and earn rewards.

Program Overview

What is the Bug Bounty Program?

Our Bug Bounty Platform connects security researchers, ethical hackers, and cybersecurity enthusiasts with opportunities to find and report security vulnerabilities across the web. In return for your contributions, you earn reputation points, credits, and real rewards for your findings.

Who Can Participate?

Anyone with security research skills is welcome! Whether you are a professional penetration tester, a hobbyist security researcher, or a student learning cybersecurity — if you find a valid vulnerability, you qualify for rewards. You must comply with all applicable laws and our program rules.

1. Find

Discover security vulnerabilities in any website, API, or application across the internet

2. Report

Submit a detailed report through our secure submission form with reproducible steps

3. Earn

Get rewarded with reputation points, platform credits, and leaderboard recognition

Program Scope

What We Accept & What We Don't

In Scope

Vulnerabilities we actively reward

  • Cross-Site Scripting (XSS) — Reflected, Stored, DOM-based
  • SQL Injection & NoSQL Injection
  • Server-Side Request Forgery (SSRF)
  • Remote Code Execution (RCE)
  • Authentication & Authorization bypasses
  • Privilege Escalation vulnerabilities
  • Insecure Direct Object References (IDOR)
  • Business logic flaws with security impact
  • API security vulnerabilities
  • AI/ML model manipulation and prompt injection

Out of Scope

Issues that do not qualify for rewards

  • Denial of Service (DoS/DDoS) attacks
  • Physical attacks or social engineering
  • Self-XSS that cannot be weaponized
  • Missing HTTP security headers without exploit
  • Rate limiting bypass without impact
  • Content spoofing without actual XSS
  • SSL/TLS configuration issues
  • Email spoofing or SPF/DKIM issues
  • Clickjacking on non-sensitive pages
  • Bugs in third-party services or dependencies
Program Rules

Rules of Engagement

1

No Destruction

Do not modify or destroy any data. Use test accounts for research and avoid accessing production user data.

2

Report First

Report vulnerabilities immediately through the official submission form. Do not disclose to third parties before we resolve the issue.

3

Good Faith Testing

Perform testing only on designated targets. Use minimal impact techniques to verify vulnerabilities.

4

No Extortion

Never threaten or demand payment. This program operates on mutual respect and responsible disclosure principles.

5

Unique Findings Only

Duplicate reports will not be rewarded. The first complete and verifiable report receives credit.

6

Quality Matters

Provide clear, reproducible steps. Include proof-of-concept code, screenshots, or video demonstrations.

Reward Tiers

Bounty Rewards

SeverityReputation PointsCredits
Critical500 rep10,000 credits
High250 rep5,000 credits
Medium100 rep2,000 credits
Low50 rep500 credits
Informational10 rep100 credits

Rewards are issued after the vulnerability is confirmed and resolved. Higher severity findings receive priority triage.

Responsible Disclosure

Disclosure Policy

We are committed to protecting our users and infrastructure. We ask that all security researchers follow responsible disclosure practices:

  • Submit your report privately through our official submission system — do not disclose vulnerabilities publicly before we have addressed them.
  • Allow us a reasonable timeframe (typically 90 days) to investigate and remediate the issue before any public disclosure.
  • We will acknowledge receipt of your report within 48 hours and provide regular updates on the remediation progress.
  • We do not pursue legal action against security researchers who act in good faith and comply with this disclosure policy.

Ready to hack?

Join the Bug Bounty Program and start earning rewards for your security research across the web today.

$ bounty --status
✓ Program Status: ACTIVE
✓ Submission System: OPEN
✓ Rewards: AVAILABLE