🛡️ Bug Bounty & Responsible Disclosure Policy

Users' privacy and security are core pillars of Screener. We welcome responsible disclosure of security vulnerabilities and reward findings that improve the security and privacy of our users.

🔍 Scope

We consider security vulnerabilities that:

  • Compromise user data or privacy
  • Allow unauthorized access to user accounts or data
  • Enable privilege escalation, remote code execution, or authentication bypass
  • Lead to injection (SQLi, XSS, CSRF, etc.) or other systemic security flaws

If your finding demonstrates a clear and reproducible impact on confidentiality, integrity, or availability, you’re in scope.

🚫 Out of Scope

The following are not considered security vulnerabilities (though we may still reward minor findings at our discretion):

  • Rate-limit or quota bypasses that don’t affect user data or system stability
  • Logic bugs that only impact UI, workflow, or non‑sensitive features (e.g., exceeding alert limits)
  • Automated spam, brute force, or flood attempts without privilege escalation
  • Missing or weak rate limits, CAPTCHAs, or email throttling
  • Design choices (such as not requiring email verification)
  • Issues affecting only outdated browsers, beta environments, or third‑party integrations
  • Configuration hardening suggestions by themselves (for example HSTS/CSP/header tuning, TLS/cipher preferences, or DNSSEC recommendations) without a proof of misuse or demonstrated security impact

In short: if it doesn’t pose a security risk, it’s not a security bug.

💰 Rewards

Rewards depend on severity and impact, following general industry guidelines but tailored to our context:

Severity Example (keywords only) Typical Reward
High Auth bypass, SQLi, account takeover ₹10,000–50,000
Medium Sensitive data leak, XSS, leaks in APIs ₹5,000–15,000
Low Minor access-control issues, info leak ₹1,000–5,000
Informational Logic or rate-limit quirks, spam, UX abuse ₹0–2,500

Rewards are discretionary and depend on clarity of report, reproducibility, and impact.

🧾 Duplicate Reports

We generally reward the first valid, reproducible report for a vulnerability.

Later reports of the same root cause are treated as duplicates and are usually not eligible for bounty rewards.

At our discretion, we may offer a partial reward if a duplicate report adds material new information (for example, a stronger proof of exploitability or significantly higher impact).

Priority is based on when we receive a complete report with reproducible steps or PoC.

🧭 Reporting Guidelines

Please include:

  • A clear description of the issue
  • Exact steps to reproduce
  • Screenshots or short videos when possible
  • An explanation of the impact (what’s at risk, and for whom)

For hardening-related reports (for example HSTS/CSP/TLS/DNSSEC), please include a proof of misuse and demonstrated impact. Without that, such reports are generally treated as informational and may not qualify for bounty rewards.

Send reports to: support@screener.in

We’ll acknowledge valid submissions within a few business days and update you as we investigate and fix.

🧘‍♀️ Responsible Disclosure

Please:

  • Do not publicly disclose vulnerabilities until we confirm they are fixed
  • Do not access or modify other users’ data
  • Do not run automated scanners or cause service disruption