Vulnerability and Bug Disclosures

Vulnerability and Bug Disclosures

Our development team rapidly investigates all reported vulnerability and security and issues. If you believe you have discovered a bug in our system, please get in touch with us. We request that you do not publicly disclose the issue until it has been addressed by us.

To show appreciation for researchers who help us keep our users safe, we operate a reward program for responsibly disclosed vulnerabilities. We reward the confidential disclosure of any design or implementation issue that could be used to compromise the confidentiality or integrity of our users’ data.

A reward of $50 USD may be provided for the disclosure of qualifying bugs. This is at our discretion, and we may increase or decrease the reward amount based on the creativity or severity of the bugs. If you report a vulnerability that does not qualify under the above criteria, we may still provide a reward if your report causes us to take specific action to improve our security.

We ask that you use common sense when looking for security bugs. Vulnerabilities must be disclosed to us privately with a reasonable time to respond, and that avoid compromise of other users, accounts and our system. We do not reward denial of service, spam, or social engineering vulnerabilities. Although our direct service are eligible, vulnerabilities in third-party applications are not.

Restrictions

  • We will only reward the first report of a bug to us
  • Any bugs or issues that are publicly disclosed without providing a reasonable time to respond will not be rewarded
  • Whether to reward the disclosure of a bug and the amount of the reward is entirely at our discretion, and we may cancel the program at any time
  • Your testing must not violate any laws
  • We cannot provide you a reward if it would be illegal for us to do so, such as to residents of countries under current U.S. sanctions