Bug Bounty &
Vulnerability Disclosure
Our Bug Bounty & Vulnerability Disclosure Program aims to foster collaboration with the security community, ensuring the protection of our systems and customer data.
We invite security researchers, ethical hackers, and security professionals to identify and report vulnerabilities in our applications.
Report a vulnerability
Some frequently asked questions
What type of vulnerabilities are in scope?
Please focus on identifying vulnerabilities in the following areas:
Web applications
Infrastructure and APIs
Out-of-scope vulnerabilities include:
Social engineering and phishing attacks
Physical attacks
Attacks requiring extensive user interaction
What do rewards look like?
We offer monetary rewards for discovered vulnerabilities, based on their severity and impact. Reward amounts range from $100 to $10,000, depending on the type and criticality of the identified issue.
What are the rules and guidelines?
- Do not engage in destructive or disruptive activities.
- Avoid compromising customer data or violating user privacy.
- Do not publicly disclose the vulnerability before the resolution.
- Adhere to all applicable laws and regulations.
By participating in the program, you agree to abide by these rules and guidelines.