We are always happy to have any bug report, and we do issue security certificates for small things that we can verify. We will also offer a bounty for bugs fitting the below criteria. The amount is based on the severity. Keep in mind we are a small startup, not Facebook or Twitter; we don't have a scale on bounty amounts, and we will pay what we can.
β
The bug would need to have a proof of concept that is:
a realistic attack vector,
expose private data, allow for unintended private operations, or seriously exploit our platform (and not just a best practice report), and
not already known by our team.
Frontend/React bugs are not eligible for bug bounties.
β
Contact us through Intercom or at [email protected].