Bug Bounty Program
If you believe you have found a security issue or vulnerability, please submit the report to our security team by following the guidelines below
Updated December 12, 2021
This program excludes (regardless of coverage indicated above):
- Clickjacking
- External SSRF
- Anything related to Mail Server Domain Misconfiguration (including email spoofing, missing DMARC, SPF/DKIM, etc.)
- Brute Force attacks on our Login or Forgot Password pages
- Account lockout enforcement
- Internal IP address disclosure
- Username / Email Enumeration
- No Captcha / Weak Captcha / Captcha Bypass
- Missing HTTP security headers
- Cookie Issues
- SSL Issues
- Weak password policies (length, complexity, etc.)
- Vulnerabilities primarily caused by browser/plugin defects and not representative of defects in the security of Bright Security’s platform
- Vulnerabilities that require social engineering
- WordPress “issues” such as xmlrpc that are mitigated by our hosting provider
- Out-of-date browsers and plugins
- Vulnerabilities in 3rd party applications that do not directly affect our data or service
- Spam of any kind
- Denial of service attacks
- Issues already known by us or previously reported to us by others
- Issues that we have determined to be of acceptable risk
Act responsibly
The rules of responsible disclosure of vulnerabilities include, but are not limited to:
- Avoid accessing, exploiting, or exposing any customer data other than your own.
- Avoid any action that may cause a degradation of our services
- Do not use any social engineering techniques
- When methods are used that do not comply with your local law and/or the above-mentioned responsibility rules, enforcement authorities will be notified

Reward
We base all payouts on impact and will reward accordingly. Please emphasize the impact as part of your submission.
We are particularly interested in:
- Major exposures around customer data leak
- Issues that result in full compromise of a system
- Business logic bypasses resulting in significant impact
- Major operational failure (excluding Denial of Service related submissions)

