Responsible disclosure

Security

Our users are bug bounty hunters. It would be absurd to pretend this site is flawless — so here is how to tell us when it isn't.

Reporting

Email [email protected] with enough detail to reproduce the issue. We acknowledge within 72 hours and aim to give you a full assessment within 14 days.

What's in scope

bounterland.com and its subdomains. We're particularly interested in authorization flaws (IDOR), anything that could forge or inflate the reputation system, and account-takeover paths.

Rules

  • Don't access, modify or delete data belonging to other people. Use your own accounts to demonstrate impact.
  • No denial of service, no spam, no social engineering of our users or staff.
  • Give us a reasonable window to fix things before going public.

What you get

We're pre-revenue, so there's no bounty pool yet — we won't insult you by pretending otherwise. What we can offer is a fast, technical response from someone who actually reads your report, public credit in our hall of fame if you want it, and a standing commitment that we will never pursue legal action against anyone who follows this policy in good faith.

Machine-readable

See /.well-known/security.txt.