Rewards under this program are discretionary and are offered as a way to recognize high-quality, high-impact reports. Submitting a valid vulnerability does not by itself guarantee a monetary reward. We consider factors such as severity, impact, report quality, and novelty when deciding whether — and how much — to reward.
Where we do issue a reward, we aim to fall within the following guideline ranges. These are indicative only, are subject to available budget, and may be adjusted or paused at any time; the version of this policy in effect at the time of your report applies.
| Severity |
Critical |
High |
Medium |
Low |
| Guideline Reward (USD) |
$300 – $2000 |
$100 – $300 |
$50 – $100 |
$10 – $50 |
Even where a monetary reward is not offered, we will always acknowledge your contribution and, with your consent, credit you publicly (see Section 10).
Reward evaluation. Within each range, the final amount is based on:
- Realistic impact scope (single user / multiple users / entire platform).
- Exploitation complexity and preconditions.
- Whether sensitive data or core business functions are affected.
- Potential damage if exploited.
- Quality, clarity, and reproducibility of the report.
Payment, taxes, and sanctions.
- Rewards are paid in USD, exclusive of any taxes; you are responsible for taxes applicable in your jurisdiction.
- We may require identity verification (KYC) and tax documentation before payment.
- We cannot make payments to individuals or entities in countries or regions subject to applicable sanctions or export-control restrictions. Determinations of eligibility on this basis are final.