RESPONSIBLE DISCLOSURE & SECURITY PROGRAM (v2026.09)

Help us keep BotDigit secure.

We welcome security researchers to inspect our platform and report vulnerabilities responsibly. Valid findings receive Official Certificates of Honor, Security Hall of Fame listing, and Linked Freelancer Profile Security Badges. Discretionary wallet or platform rewards may be granted under applicable terms.

Security Hall of Fame Linked Freelancer Profile Badges Official Letter of Thanks Verifiable QR Certificates

Flexible Bug Bounty Reward Policy — Recognition-First Program

BotDigit operates a recognition-first security research program. Valid security findings may qualify for rewards or other forms of recognition based on the severity, impact, quality of the report, and the applicable Bug Bounty Program Terms.

Recognition-First Program

Important Notice: Cash payments and wallet credits are not guaranteed for every valid finding. A valid security report may receive official recognition without a monetary reward. Where a reward is applicable, BotDigit determines the appropriate reward after technical validation and review of actual security impact.

Separation of Validation & Rewards

The reward decision is separate from the security validation decision. A finding may therefore be classified as Valid and receive official recognition without necessarily qualifying for a monetary or wallet-based reward.

Important Notice: Cash payments and wallet credits are not guaranteed for every valid finding. A valid security report may receive official recognition without a monetary reward. Where a reward is applicable, BotDigit determines the appropriate reward after technical validation and review of actual security impact.

Severity Tiers & Recognition Rewards

Recognition includes official certificates, executive appreciation letters, and public badges. Discretionary perks may be awarded where applicable.

Recognition-First Model
🔴CriticalRecognition & Discretionary Review

Examples: Remote Code Execution (RCE), Escrow theft or unauthorized fund movement, Authentication bypass or privilege escalation to admin, Full production database compromise

🎁 Recognition: 📜 Official Verifiable Certificate of Honor · 🏆 Security Hall of Fame Listing (Honor Roll) · ✉️ Formal Executive Letter of Thanks & Appreciation · 💼 Verified Security Auditor Badge on Freelancer Profile · 🎁 Discretionary Wallet Credit or Platform Perks (where approved)

Discretionary / Recognition Tier📜 Certificate & Honors
🟠HighRecognition & Discretionary Review

Examples: Stored Cross-Site Scripting (XSS) with meaningful business impact, Sensitive PII Insecure Direct Object Reference (IDOR), Payment-flow bypass or contract manipulation, Account-takeover Cross-Site Request Forgery (CSRF)

🎁 Recognition: 📜 Official Verifiable Certificate of Honor · 🏆 Security Hall of Fame Listing (Honor Roll) · ✉️ Formal Executive Letter of Thanks & Appreciation · 💼 Verified Security Auditor Badge on Freelancer Profile · 🎁 Discretionary Wallet Credit or Platform Perks (where approved)

Discretionary / Recognition Tier📜 Certificate & Honors
🟡MediumRecognition & Discretionary Review

Examples: Reflected XSS requiring minimal user interaction, Subdomain takeover on active corporate domains, Broken access control on non-critical endpoints or user metadata, Logic flaws permitting unauthorized feature access

🎁 Recognition: 📜 Official Verifiable Certificate of Honor · 🏆 Security Hall of Fame Listing (Honor Roll) · ✉️ Formal Executive Letter of Thanks & Appreciation · 💼 Verified Security Auditor Badge on Freelancer Profile

Discretionary / Recognition Tier📜 Certificate & Honors
🔵LowRecognition Tier

Examples: Open redirect with actionable phishing potential, Information disclosure of non-sensitive environmental data, Missing security headers with demonstrated actionable exploit PoC, CORS misconfigurations exposing non-sensitive data

🎁 Recognition: 📜 Official Verifiable Certificate of Honor · 🏆 Security Hall of Fame Listing (Honor Roll) · ✉️ Formal Letter of Thanks & Appreciation

Recognition Tier📜 Acknowledgment Only
⚪InformationalRecognition Tier

Examples: Security hardening recommendations & best practices, Theoretical weaknesses without demonstrated exploitability, Reports outside monetary criteria or non-exploitable findings

🎁 Recognition: 📜 Certificate of Acknowledgment · 🏆 Security Hall of Fame Listing (Honor Roll) · ✉️ Official Letter of Thanks

Recognition Only📜 Acknowledgment Only

What Counts as a Valid Security Finding?

To qualify for technical review and potential bounty consideration, every disclosure must satisfy the following baseline criteria:

Affects an in-scope BotDigit production asset or API endpoint.
Represents a genuine security vulnerability or meaningful security weakness.
Is fully reproducible with unambiguous, step-by-step instructions.
Includes clear technical evidence (HTTP request/response logs, PoC script, or screenshot).
Demonstrates realistic, actionable security impact under realistic conditions.
Is NOT a duplicate of an existing report or an already known issue.
Strictly complies with responsible disclosure and testing constraints.
Avoids all prohibited testing techniques (no DoS, no data destruction, no privacy breach).
Does not intentionally damage users, infrastructure, or platform availability.

Duplicate Report Policy

First Valid Researcher: The first independently submitted, sufficiently reproducible report is eligible for primary recognition and reward review.

Duplicate Reports: Subsequent duplicate reports describing the same underlying issue or root cause generally do not receive an additional award. Multiple reports describing the same underlying vulnerability are treated as one finding.

BotDigit may evaluate evidence of independent discovery when determining recognition-only awards (certificates and Hall of Fame acknowledgments).

Severity Is Not Self-Declared

Researchers select a preliminary severity rating during submission to assist initial triage.

However, the preliminary severity is not final. BotDigit's security team reassesses the final severity based on demonstrated exploitability, required attack prerequisites, realistic business impact, and affected assets.

Selecting "Critical" in the submission form does not automatically entitle the report to the Critical reward range.

In-Scope Targets

An endpoint being technically accessible does not automatically make every associated behavior eligible for a bounty.

  • botdigit.com — Primary Marketplace & Freelance Workspace App
  • botdigit.com/api/v1/* — Backend Gateway Microservices & Auth Endpoints
  • Escrow & Smart Contract APIs — Payment Transaction Verification & Release Systems
  • BotDigit Wallet APIs — Internal Ledger, Top-Up & Payout Handlers

Out-of-Scope & Prohibited Targets

  • Admin infrastructure, internal staging databases, and production vault secrets
  • Spam, phishing, social engineering, physical security, or credential stuffing
  • DoS/DDoS attacks, volume-based fuzzing, or automated vulnerability scanner dumps
  • Self-XSS (unless chained to actionable privilege escalation)
  • Missing security headers or TLS cipher observations without a working exploit PoC
  • Public disclosure before the 30-day responsible disclosure window has elapsed

Testing Standards & Prohibition of Degradation

Required Safe Testing Conduct

  • •Use only researcher-owned test accounts for validation.
  • •Execute minimal requests required to demonstrate technical proof of concept.
  • •Immediately halt testing upon confirming vulnerability existence.
  • •Handle any inadvertently accessed data with strict confidentiality.

Prohibited Testing Activities

  • •Do not access, download, or inspect another user's private data beyond the absolute minimum required to prove the flaw.
  • •Do not modify, corrupt, or delete production data or user records.
  • •Do not transfer, escrow, or withdraw funds belonging to other users.
  • •Do not perform destructive database queries or account lockouts.
  • •Do not conduct high-volume traffic tests, stress tests, or automated scanner dumps.
  • •Do not disrupt platform availability or cause service degradation.
  • •Do not execute physical attacks, phishing, social engineering, or spam against BotDigit staff or users.
Rate Limiting & Degradation Rule: Researchers must immediately stop or reduce testing if their activities cause service degradation, abnormal resource consumption, account disruption, or noticeable platform slowdown. A valid vulnerability does NOT authorize unlimited or abusive testing.

BotDigit Wallet Credit & Platform Perks (When Approved)

Financial Transparency

When an optional or discretionary Wallet Top-Up Credit is expressly granted, it is deposited into the researcher's BotDigit Wallet.

🛍️ Spend on Platform

Credits can be used immediately to fund freelancer contracts, escrow milestone deposits, or purchase digital products.

🏦 Payout / Withdrawal

Eligible wallet balances may be withdrawn to cryptocurrency (USDT/USDC) or bank accounts, subject to account KYC verification and standard network fees.

✨ 100% Fee-Exempt

Unlike freelance revenue which incurs a 10% platform fee, bug bounty rewards are 100% exempt from platform marketplace commissions.

Triage Lifecycle & 30-Day Confidentiality

Researchers must keep all vulnerability information strictly confidential while BotDigit investigates and deploys remediation. Researchers must not publicly disclose the vulnerability during the first 30 days following acknowledgment unless BotDigit provides express prior written authorization.

Step 1

Submission

Researcher submits complete report with reproduction steps and PoC.

Step 2

Acknowledgment

Security Desk provides tracking ID within target SLA (48h initial response).

Step 3

Triage & Validation

Security engineers verify scope, reproducibility, impact, and duplicate status.

Step 4

Decision

Finding is categorized as Valid + Reward Eligible, Valid + Recognition Only, Duplicate, Informational, Out of Scope, or Invalid.

Step 5

Recognition & Remediation

Certificates and Hall of Fame honors are published, patches deployed, and any discretionary credit credited.

Requesting Reconsideration

Researchers may request formal reconsideration of severity assignments, duplicate determinations, reward eligibility, or recognition status by replying to their ticket email or contacting [email protected] with technical justification. Good-faith appeals and technical discussions are always welcomed.

Responsible Disclosure Program Terms & Researcher Conduct

Program Terms

By submitting a vulnerability disclosure report to BotDigit, security researchers agree to conduct themselves in good faith under the following terms:

1. Non-Coercion & Good Faith

Researchers must not threaten public disclosure to force payment, demand compensation outside the published program, or threaten users or personnel. Legitimate, good-faith technical questions and appeals regarding bounty decisions are explicitly welcomed and do not constitute coercion.

2. Confidentiality & Public Disclosure

Researchers must keep findings confidential during the initial 30-day investigation and patching window. Researchers must not knowingly publish false factual claims, fabricate proof of concept evidence, or impersonate BotDigit personnel.

3. Program Framework & Discretion

Published bounty ranges describe the program's reward framework. Submitting a report does not create an unconditional monetary debt. Final bounty amounts are determined following technical review of impact and exploitability.

4. Non-Retroactive Program Application

The applicable bounty rules are those published and accepted at the time the report is submitted. Future updates or modifications apply prospectively to reports submitted after updated terms become effective.

Submit a Security Report

You will receive a tracking reference ID. Our security desk targets an initial acknowledgment response within 48 hours target.

By submitting, you agree to BotDigit's Responsible Disclosure Program Terms (v2026.09).

Program Version: 2026.09 · Effective Date: September 24, 2026
Last Updated: September 24, 2026

Questions regarding our security program? Contact our security desk directly at [email protected]

HomeJobs
Get Started
ExploreSign In