Skip to main content
Bug Bounties

An overview of our current bug bounty policy.

Derek Labian avatar
Written by Derek Labian
Updated over 4 years ago

We are always happy to have any bug report, and we do issue security certificates for small things that we can verify. We will also offer a bounty for bugs fitting the below criteria. The amount is based on the severity. Keep in mind we are a small startup, not Facebook or Twitter; we don't have a scale on bounty amounts, and we will pay what we can.


​

The bug would need to have a proof of concept that is:

  1. a realistic attack vector,

  2. expose private data, allow for unintended private operations, or seriously exploit our platform (and not just a best practice report), and

  3. not already known by our team.

Frontend/React bugs are not eligible for bug bounties.


​

Contact us through Intercom or at [email protected].

Did this answer your question?