Divulgation responsable
Ce document est disponible en anglais. Seule la version anglaise fait foi.
Version: 1.0
Effective Date: October 13, 2025
Acknowledgment within 48 hours and status updates every 7 business days. Contact: support@passguard.com
1. Overview
Passguard values the security research community. We operate EU-hosted services that help detect and respond to infostealer infections. If you discover a vulnerability affecting Passguard assets, please report it responsibly so we can fix it and reward you appropriately.
2. In-scope Assets
| Product | Host / Asset | Notes |
| Website | passguard.com | Public website (marketing, docs, blog, KB). Also in scope: any other asset clearly owned and operated by Passguard. |
| Platform | app.passguard.com | Customer-facing app/dashboards, auth, alerts, data. |
| External API (Production) | api.passguard.com | Customer/partner API (keyed, production). |
| Screening Portal | passguard.app | Screening/search portal. |
| API Hub (Developer Portal) | app.passguard.dev | Important: developer console, key issuance/rotation, docs, sample apps. Elevated sensitivity. |
| Dev API (Sandbox) | api.passguard.dev | Mock data only, intentionally works without an API key. Lower payouts (25–50% of production) unless systemic/production impact is demonstrated. |
| Internal API | Private/internal domains | In scope if publicly reachable and a valid vulnerability is demonstrated. Eligible for 2× the standard bounty. |
3. Out of Scope (unless chainable to real impact)
- Third-party services not owned by Passguard.
- DoS/DDoS, traffic flooding, or resource-exhaustion tests.
- Social engineering, phishing of staff/customers.
- Purchasing or interacting with criminal marketplaces on our behalf.
- Automated mass scanning beyond rate limits (see Rules of Engagement).
- Cosmetic issues or missing headers without a practical exploit path.
4. Rules of Engagement
- Do no harm: use your own/test accounts; do not access, modify, or exfiltrate real customer data.
- Default rate limit ≤ 5 requests/second. No stress/load testing without prior written approval.
- Identify research traffic (e.g., User-Agent: security-research/ and X-Passguard-Researcher: ).
- Stop and report immediately if you encounter sensitive data; capture minimal evidence only.
- No public disclosure before fix and explicit written permission from Passguard.
- Comply with applicable laws; act in good faith at all times.
5. Weighting & Evaluation (within severity bands)
Within each severity category, the exact payout depends on a combination of factors: severity & exploitability, business impact (data sensitivity/scale), report quality (clarity, reproduction steps, safe PoC), fix support (mitigation ideas/patch suggestions), and responsiveness during triage.
6. Bounty Table
Payouts reflect industry standards adjusted for Passguard’s context. Multipliers may apply per asset (e.g., API Hub may warrant the higher end of a band; Dev API generally pays at 25–50% unless production impact is demonstrated).
| Severity | Typical Examples | Payout (€) |
| Low | Clickjacking; open redirect without token theft; minor misconfigurations. | 50 – 150 |
| Medium | Sensitive info disclosure (limited scope); reflected XSS with credible impact; single-user auth logic bugs. | 150 – 500 |
| High | IDOR exposing session/device data; impactful SSRF; stored XSS in analyst/admin surfaces; CSRF on critical actions; OAuth/OIDC flaws. | 500 –1.500 |
| Critical | Account takeover/auth bypass; RCE affecting production; export of non-public infection/session data; production secret exfiltration; supply-chain compromise. | 1.500 – 5.000 |
7. Payments, Taxes, and KYC
- Payment methods: bank transfer, PayPal, or another mutually agreed method.
- KYC/compliance may be required depending on payout amount and jurisdiction.
- Researchers are responsible for reporting and paying taxes in their jurisdiction.
- Duplicates: only the first valid report is eligible for payout.
- Bonuses up to 2× for exceptional reports (high-quality PoCs, thorough impact analysis, remediation guidance).
8. Reporting Template
- Your name/handle and contact email.
- Target asset (full URL/host) and environment (prod/dev).
- Short summary and business impact.
- Step-by-step reproduction: requests, headers, payloads, and responses.
- Proof-of-concept code or screenshots (redact any secrets).
- Test accounts used (prove ownership).
- Suggested remediation or mitigation (optional but appreciated).
9. Safe Harbour
Good-faith testing within this policy is authorised and will not result in legal action or law-enforcement referral by Passguard. If you inadvertently access sensitive data, stop immediately, capture minimal evidence, and report it. This safe harbour does not apply to activity outside this policy.
10. Recognition
With your consent, we will credit you on our Hall of Fame. Anonymous credit is available upon request.
11. Program Changes & Security.txt
We may adjust scope and bounty ranges over time. Updates will be reflected on this page and in security.txt.