Skip to main content

Bug Bounty Program Rules

E
Written by Elvia Amelia
Updated over 4 months ago

At Remoly Invoicing, we work hard to keep our platform safe and secure. To support this, we run a Bug Bounty Program to reward security researchers who report valid issues responsibly.

If you discover a vulnerability, please email [email protected]. Our team will review your report and respond based on priority.

Scope of the Program

The program applies to all Remoly Invoicing websites and online services that handle sensitive customer information.

What Qualifies for a Report

We accept reports about security problems that could affect the safety of user data or accounts. Examples include coding or design issues that may impact security.

When testing:

  • Only use your own account.

  • Do not try to access other users’ data.

  • Do not run DoS/DDoS attacks, spam, or anything that disrupts our services.

What Does Not Qualify

The following issues are excluded from rewards:

  • Automated scanner results.

  • Public files or directories (e.g., robots.txt).

  • Minor issues such as missing HTTP headers or SSL settings.

  • Clickjacking without real impact.

  • Logout CSRF or CSRF on simple public forms.

  • Username or email enumeration.

  • Brute force attempts on login or password reset.

  • Self-XSS or issues requiring local access.

  • SPF/DMARC or DNS errors.

  • Disclosure of non-sensitive information.

  • Email flooding or rate-limiting issues.

Some reports may also not qualify if they present little or no real security risk.

Rewards

  • Rewards are based on the seriousness and originality of the issue.

  • Higher rewards may be given for critical or clever findings.

  • Only the first valid report of a bug will be rewarded.

Responsible Disclosure

  • Act in good faith and avoid causing harm.

  • Never copy, share, or misuse real user data.

  • Do not make the issue public without our consent.

  • We aim to review reports quickly and resolve them in a reasonable time.

Legal Notes

  • We cannot reward individuals or countries under international sanctions (e.g., Cuba, Iran, North Korea, Sudan, Syria).

  • You are responsible for any taxes on rewards you receive.

  • This is a voluntary program and may be changed or cancelled at any time.

To report a vulnerability, email [email protected]. For non-security issues, please contact our support team.

Did this answer your question?