Security Bounty Program

Overview

Data security and privacy are key aspects of our service. We welcome outside help through our bounty program to make us aware of any gaps in our security.

To participate you wll need to follow a few rules:

Finally, please keep in mind this security bounty program doesn’t concern regular bugs in our application or API. We're only interested in security flaws allowing intruders to gain access to data of other users. If you wish to report a regular bug use the contact form.

Reports we're interest in

in scope

Examples of Non-Qualifying exploits

Reports we don't want

Rewards

Our reward system is flexible and doesn't have any strict upper or lower limit. The amount of the reward will depend on the severity of the vulnerability. The amount of the reward and whether or not a vulnerability qualifies will be at our sole discretion.

Rewards will be sent by bank transfer (Transferwise if the recipient is not in the Eurozone) once the vulnerability has been fixed and the reporter has supplied a valid invoice. All international transfer and conversion fees will be paid by the recipient.

We only award one bounty per vulnerability. If we receive multiple reports, the first one will receive the reward.

Report submission

Please submit to the email address in our security.txt file.

Hall of Fame

Thanks to the following researchers who have helped us debug various issues.

Start your free trial

2,500 API requests per day.

No credit card required.