🛡️ Bug Bounty & Responsible Disclosure Policy
Users' privacy and security are core pillars of Screener. We welcome responsible disclosure of security vulnerabilities and reward findings that improve the security and privacy of our users.
🔍 Scope
We consider security vulnerabilities that:
- Compromise user data or privacy
- Allow unauthorized access to user accounts or data
- Enable privilege escalation, remote code execution, or authentication bypass
- Lead to injection (SQLi, XSS, CSRF, etc.) or other systemic security flaws
If your finding demonstrates a clear and reproducible impact on confidentiality, integrity, or availability, you’re in scope.
🚫 Out of Scope
The following are not considered security vulnerabilities (though we may still reward minor findings at our discretion):
- Rate-limit or quota bypasses that don’t affect user data or system stability
- Logic bugs that only impact UI, workflow, or non‑sensitive features (e.g., exceeding alert limits)
- Automated spam, brute force, or flood attempts without privilege escalation
- Missing or weak rate limits, CAPTCHAs, or email throttling
- Design choices (such as not requiring email verification)
- Issues affecting only outdated browsers, beta environments, or third‑party integrations
- Configuration hardening suggestions by themselves (for example HSTS/CSP/header tuning, TLS/cipher preferences, or DNSSEC recommendations) without a proof of misuse or demonstrated security impact
In short: if it doesn’t pose a security risk, it’s not a security bug.
💰 Rewards
Rewards depend on severity and impact, following general industry guidelines but tailored to our context:
| Severity | Example (keywords only) | Typical Reward |
|---|---|---|
| High | Auth bypass, SQLi, account takeover | ₹10,000–50,000 |
| Medium | Sensitive data leak, XSS, leaks in APIs | ₹5,000–15,000 |
| Low | Minor access-control issues, info leak | ₹1,000–5,000 |
| Informational | Logic or rate-limit quirks, spam, UX abuse | ₹0–2,500 |
Rewards are discretionary and depend on clarity of report, reproducibility, and impact.
🧾 Duplicate Reports
We generally reward the first valid, reproducible report for a vulnerability.
Later reports of the same root cause are treated as duplicates and are usually not eligible for bounty rewards.
At our discretion, we may offer a partial reward if a duplicate report adds material new information (for example, a stronger proof of exploitability or significantly higher impact).
Priority is based on when we receive a complete report with reproducible steps or PoC.
🧭 Reporting Guidelines
Please include:
- A clear description of the issue
- Exact steps to reproduce
- Screenshots or short videos when possible
- An explanation of the impact (what’s at risk, and for whom)
For hardening-related reports (for example HSTS/CSP/TLS/DNSSEC), please include a proof of misuse and demonstrated impact. Without that, such reports are generally treated as informational and may not qualify for bounty rewards.
Send reports to: support@screener.in
We’ll acknowledge valid submissions within a few business days and update you as we investigate and fix.
🧘♀️ Responsible Disclosure
Please:
- Do not publicly disclose vulnerabilities until we confirm they are fixed
- Do not access or modify other users’ data
- Do not run automated scanners or cause service disruption