Bug Bounty Program
Help us keep AuraGuardian secure. Report vulnerabilities responsibly and get recognized in our Hall of Fame.
In-Scope Vulnerabilities
We accept reports for the following vulnerability categories on AuraGuardian production systems.
Injection
criticalSQL injection, command injection, LDAP injection, and other server-side injection flaws.
Authentication Bypass
criticalBypassing login, 2FA, session management, or privilege escalation vulnerabilities.
XSS / Client-side
highStored and reflected cross-site scripting, DOM-based XSS, and HTML injection.
SSRF
highServer-Side Request Forgery allowing access to internal services or metadata endpoints.
Data Exposure
highUnintended exposure of sensitive user data, API keys, credentials, or internal configurations.
RCE
criticalRemote Code Execution via file upload, deserialization, template injection, or eval flaws.
✕ Out of Scope
- Social engineering / phishing attacks
- Denial of service (DoS / DDoS) attacks
- Vulnerabilities in third-party services
- Issues requiring physical access to a device
- Clickjacking on pages with no sensitive actions
- Missing security headers without demonstrable impact
- Rate limiting issues on non-sensitive endpoints
Rules of Engagement
Please follow these guidelines for responsible disclosure.
Hall of Fame
Security researchers who have helped make AuraGuardian safer.
Be the first to be recognized
Find a valid vulnerability in AuraGuardian and earn a permanent place in our Hall of Fame. Every report helps secure the entire network.
Submit a ReportSubmit a Vulnerability
Found something? Let us know. All reports are reviewed by our security team.