BUG BOUNTY PROGRAM

Help us improve OptiArms' security by finding and reporting vulnerabilities. Earn rewards for qualifying submissions.

SUBMIT A VULNERABILITY

Important: Please provide detailed information about the vulnerability to help us understand and reproduce the issue. All submissions are subject to verification.

PROGRAM DETAILS

The OptiArms Bug Bounty Program rewards security researchers who help us identify and fix vulnerabilities in our platform. We are committed to addressing security issues promptly and transparently.

REWARD STRUCTURE

Severity Description Reward Range
Critical Remote code execution, full system access $5,000 - $10,000
High Auth bypass, data exposure, SQL injection $1,000 - $5,000
Medium XSS, CSRF, logic flaws with security impact $500 - $1,000
Low Minor issues with limited impact $100 - $500

IN SCOPE

  • OptiArms web application (app.optiarms.com)
  • OptiArms API endpoints (api.optiarms.com)
  • OptiArms mobile applications
  • OptiArms detection algorithms
  • OptiArms edge processing modules

OUT OF SCOPE

  • Social engineering attacks
  • DoS/DDoS attacks
  • Physical security issues
  • Third-party services/CDNs
  • Findings from automated tools without verification

RULES OF ENGAGEMENT

Do No Harm

Test in a way that avoids data destruction, service disruption, or harm to others. Never attempt to access, modify, or destroy data that doesn't belong to you.

Responsible Disclosure

Allow us 90 days to address the vulnerability before any public disclosure. We aim to fix critical issues within 7 days.

Quality Reports

Submit detailed reports with clear reproduction steps. Higher quality reports receive priority evaluation and are eligible for higher rewards.