️ INVITE-ONLY · BETA

SEcMS Bug Bounty Program

Report security vulnerabilities responsibly. Get rewarded.

Reward Tiers

SeverityExamplesReward RangeResponse SLA
CriticalRCE, Auth bypass, mass PII leak$2,000 – $10,00024h
HighStored XSS, SQLi, privilege escalation$500 – $2,00048h
MediumReflected XSS, CSRF in sensitive flow, info disclosure$100 – $5007d
LowSelf-XSS, missing security headers, theoretical issuesHall of Fame + swag30d

Scope

In-Scope

Out-of-Scope

Rules of Engagement

How to Report

Email: [email protected]

PGP Key: coming soon — currently TLS-only acceptable

Required info:

  1. Vulnerability title + severity self-assessment
  2. Affected endpoint / component (URL + method)
  3. Reproduction steps (numbered)
  4. Proof-of-concept (curl command, screenshot, video)
  5. Impact analysis (what an attacker can achieve)
  6. Suggested mitigation (optional)
  7. Your name / handle for Hall of Fame (optional)

Disclosure Timeline

DayAction
T+0Researcher submits report
T+1dAcknowledgement (Critical/High)
T+7dTriage decision + reward indication
T+30dPatch deployed (Critical/High)
T+90dPublic disclosure (coordinated)

Hall of Fame

Researchers who responsibly disclosed vulnerabilities will be listed here (with consent).

Hall of Fame is empty (Beta program just launched 2026-05-05).
Be the first

Legal Safe Harbor

We will not pursue civil or criminal action against researchers who:

Last updated: 2026-05-05 · Maintained by we are Corp. Security Team
Questions? [email protected]