BUG BOUNTY PROGRAM

Help us improve OptiArms' security by finding and reporting vulnerabilities. Earn rewards for qualifying submissions.

SUBMIT A VULNERABILITY

Important: Please provide detailed information about the vulnerability to help us understand and reproduce the issue. All submissions are subject to verification.

PROGRAM DETAILS

The OptiArms Bug Bounty Program rewards security researchers who help us identify and fix vulnerabilities in our platform. We are committed to addressing security issues promptly and transparently.

REWARD STRUCTURE

Severity Description Reward
Critical Remote code execution, full system access Highest Tier
High Auth bypass, data exposure, SQL injection High Tier
Medium XSS, CSRF, logic flaws with security impact Medium Tier
Low Minor issues with limited impact Recognition

Note: Reward amounts are determined on a case-by-case basis depending on severity, impact, and report quality. Contact security@optiarms.com for more information about our reward structure.

IN SCOPE

  • OptiArms web application (app.optiarms.com)
  • OptiArms API endpoints (api.optiarms.com)
  • OptiArms mobile applications
  • OptiArms detection algorithms
  • OptiArms edge processing modules

OUT OF SCOPE

  • Social engineering attacks
  • DoS/DDoS attacks
  • Physical security issues
  • Third-party services/CDNs
  • Findings from automated tools without verification

RULES OF ENGAGEMENT

Do No Harm

Test in a way that avoids data destruction, service disruption, or harm to others. Never attempt to access, modify, or destroy data that doesn't belong to you.

Responsible Disclosure

Allow us 90 days to address the vulnerability before any public disclosure. We aim to fix critical issues within 7 days.

Quality Reports

Submit detailed reports with clear reproduction steps. Higher quality reports receive priority evaluation and are eligible for higher rewards.