Responsible Disclosure Guidelines
Our rules of engagement to ensure safe, legal, and effective security research.
✅ What You Should Do
-
Read the program scope carefully
Each program has specific targets and rules. Only test systems explicitly listed in scope.
-
Use your own accounts
Create test accounts when possible. Never use real customer data or accounts.
-
Document everything
Take screenshots, save HTTP requests/responses, and provide clear reproduction steps.
-
Report promptly
Submit your findings as soon as possible. Don't share vulnerabilities with others before disclosure.
-
Be patient
Allow time for triage and patching. Response times vary by program.
❌ What You Should NOT Do
Engaging in any of the following will result in immediate disqualification and potential legal action.
-
Never access non-public data
Don't view, download, or store customer data or personal information.
-
Don't modify or delete data
Never alter, delete, or corrupt data in any system.
-
No Denial of Service attacks
Don't attempt to overwhelm systems with excessive traffic.
-
Don't exploit beyond proof-of-concept
Stop once you've confirmed the vulnerability. Don't pivot to other systems.
-
No social engineering
Don't attempt to manipulate employees or support staff.
-
Don't share vulnerabilities
Keep findings confidential until disclosed by the program.
Scope Rules
🟢 In Scope
- Explicitly listed domains/subdomains
- Mobile applications listed in program
- API endpoints documented in scope
- Third-party integrations (if specified)
🔴 Out of Scope
- Subdomains not explicitly listed
- Third-party services (unless specified)
- SPAM, phishing, or social engineering
- Physical security testing
Reward Structure
Submission Process
Submit Report
Use our submission form with detailed reproduction steps.
Triage
Our team reviews and validates your report within 2-5 business days.
Assessment
Severity is assigned based on CVSS and business impact.
Reward
Points and cash rewards are processed after verification.
Legal Protection
We support the principles of responsible disclosure. When you follow these guidelines:
- We will not pursue legal action against you for good-faith security research
- We will work with you to understand and resolve issues promptly
- We will acknowledge your contribution (with your consent)