Bug bounty
There is no funded reward program and no managed disclosure inbox today. This page covers what is safe to test and how to reach us without exposing a vulnerability.
Status
No rewards are confirmed or funded. Nothing here is an offer of payment. There is no verified email address, form or portal for vulnerability reports.
Safe scope
In scope for good-faith testing
- The simulated browser demo, in your own browser.
- The public API, using data you create yourself.
- Signature, verification and input-validation logic.
- Information exposed that this site says is not stored.
Out of scope
- Other people's data or accounts.
- Denial of service, load testing, spam or brute force.
- Social engineering or physical attacks.
- Third-party services and shielded pools.
- Anything involving real funds.
Exclusions
- Reports that the demo is simulated, resets on refresh or does not hide your IP. These are documented behavior.
- Recipient and link data being visible to the recipients and public link holders it is meant for.
- Missing hardening headers without a demonstrated impact.
- Automated scanner output with no proof of exploitability.
How to report
- Do not post details publiclyPublic posts, replies and issues can be read by everyone, including attackers.
- Ask for a private channelMessage the official X account @UseZeroshade and say only that you have a security report and need a private channel.
- Wait for a replyDo not share sensitive vulnerability details until a private channel is confirmed. No response time is promised.
Public X is only for requesting that channel, never for the vulnerability itself.
Good-faith rules
- Use only your own test data.
- Stop when you can show a problem. Do not pull data you do not own.
- Do not publish before the issue is addressed or a channel owner agrees.