Policy v4.2 · updated Jun 12, 2026

Responsible disclosure.

The rules of engagement for testing HuntBug itself and every program hosted on the platform. Short version: act in good faith, stay in scope, report fast — and the law is on your side.

Safe harbor, guaranteed.

Security research conducted in accordance with this policy is authorized under the Computer Fraud and Abuse Act and equivalent laws in your jurisdiction. We will not initiate legal action against you, and we will state plainly to any third party that your research was authorized. If a program on HuntBug attempts to pursue a good-faith researcher, we terminate the program.

§ 01 — REPORTING CHANNEL

One door, always open

All reports go through the platform — never email, never DMs. Submissions are encrypted at rest, timestamped for priority, and hashed for duplicate detection. If HuntBug itself is the target, use the huntbug-core program.

§ 02 — SCOPE

The scope page is law

Each program's scope page lists in-scope assets, out-of-scope assets, and excluded vulnerability classes. Scope changes are versioned and take effect on publish — a finding made in scope stays in scope for reports filed within 72 hours of the change.

§ 03 — DATA HANDLING

Touch the minimum

Access only what's needed to demonstrate impact. If you encounter personal data, stop, capture the minimum evidence, and report immediately. Never exfiltrate, store, or share user data — one redacted record proves the point.

§ 04 — DISCLOSURE TIMELINE

Coordinated, not silent

Default disclosure window is 90 days from triage acceptance, extendable once by 30 days with written rationale. After the window, you may publish with the program's severity rating and payout attached.

Response clocks we're held to

SeverityDefinitionFirst responseTriage decisionBounty decision
CriticalRCE, auth bypass, mass data exposure2 hours24 hours7 days
HighPrivilege escalation, stored XSS, SSRF with reach8 hours3 days14 days
MediumIDOR with limited blast radius, CSRF on state changes24 hours7 days21 days
LowOpen redirects, verbose errors, rate-limit gaps72 hours14 days30 days

Do this, never that

+Always fine

  • Test with your own accounts — create as many as scope allows.
  • Chain findings to demonstrate realistic impact.
  • Use automation within each program's published rate limits.
  • Report suspected duplicates — the earlier timestamp wins, partial credit applies.
  • Ask triage before going deeper on anything ambiguous.

×Instant policy violation

  • Social engineering — phishing, vishing, or pretexting staff or users.
  • Physical access attempts against offices or data centers.
  • Denial of service, resource exhaustion, or destructive payloads.
  • Pivoting to third parties not named in scope.
  • Extortion framing — conditioning a report on payment voids safe harbor immediately.

If the platform itself is down

contact: security@huntbug.com
pgp: 4F2A 91C8 07BD 3E5A 66D1   09FA 4C77 21B8 D3E0 5A9C
policy: https://huntbug.com/security.txt
expires: 2027-06-12T00:00:00Z

Found something right now? Median time from submission to first human response: 1h 47m.

Report a vulnerability in HuntBug