Help us keep BotDigit secure.
We welcome security researchers to inspect our platform and report vulnerabilities responsibly. Valid findings receive Official Certificates of Honor, Security Hall of Fame listing, and Linked Freelancer Profile Security Badges. Discretionary wallet or platform rewards may be granted under applicable terms.
Flexible Bug Bounty Reward Policy — Recognition-First Program
BotDigit operates a recognition-first security research program. Valid security findings may qualify for rewards or other forms of recognition based on the severity, impact, quality of the report, and the applicable Bug Bounty Program Terms.
Recognition-First Program
Important Notice: Cash payments and wallet credits are not guaranteed for every valid finding. A valid security report may receive official recognition without a monetary reward. Where a reward is applicable, BotDigit determines the appropriate reward after technical validation and review of actual security impact.
Separation of Validation & Rewards
The reward decision is separate from the security validation decision. A finding may therefore be classified as Valid and receive official recognition without necessarily qualifying for a monetary or wallet-based reward.
Severity Tiers & Recognition Rewards
Recognition includes official certificates, executive appreciation letters, and public badges. Discretionary perks may be awarded where applicable.
Examples: Remote Code Execution (RCE), Escrow theft or unauthorized fund movement, Authentication bypass or privilege escalation to admin, Full production database compromise
🎁 Recognition: 📜 Official Verifiable Certificate of Honor · 🏆 Security Hall of Fame Listing (Honor Roll) · ✉️ Formal Executive Letter of Thanks & Appreciation · 💼 Verified Security Auditor Badge on Freelancer Profile · 🎁 Discretionary Wallet Credit or Platform Perks (where approved)
Examples: Stored Cross-Site Scripting (XSS) with meaningful business impact, Sensitive PII Insecure Direct Object Reference (IDOR), Payment-flow bypass or contract manipulation, Account-takeover Cross-Site Request Forgery (CSRF)
🎁 Recognition: 📜 Official Verifiable Certificate of Honor · 🏆 Security Hall of Fame Listing (Honor Roll) · ✉️ Formal Executive Letter of Thanks & Appreciation · 💼 Verified Security Auditor Badge on Freelancer Profile · 🎁 Discretionary Wallet Credit or Platform Perks (where approved)
Examples: Reflected XSS requiring minimal user interaction, Subdomain takeover on active corporate domains, Broken access control on non-critical endpoints or user metadata, Logic flaws permitting unauthorized feature access
🎁 Recognition: 📜 Official Verifiable Certificate of Honor · 🏆 Security Hall of Fame Listing (Honor Roll) · ✉️ Formal Executive Letter of Thanks & Appreciation · 💼 Verified Security Auditor Badge on Freelancer Profile
Examples: Open redirect with actionable phishing potential, Information disclosure of non-sensitive environmental data, Missing security headers with demonstrated actionable exploit PoC, CORS misconfigurations exposing non-sensitive data
🎁 Recognition: 📜 Official Verifiable Certificate of Honor · 🏆 Security Hall of Fame Listing (Honor Roll) · ✉️ Formal Letter of Thanks & Appreciation
Examples: Security hardening recommendations & best practices, Theoretical weaknesses without demonstrated exploitability, Reports outside monetary criteria or non-exploitable findings
🎁 Recognition: 📜 Certificate of Acknowledgment · 🏆 Security Hall of Fame Listing (Honor Roll) · ✉️ Official Letter of Thanks
What Counts as a Valid Security Finding?
To qualify for technical review and potential bounty consideration, every disclosure must satisfy the following baseline criteria:
Duplicate Report Policy
First Valid Researcher: The first independently submitted, sufficiently reproducible report is eligible for primary recognition and reward review.
Duplicate Reports: Subsequent duplicate reports describing the same underlying issue or root cause generally do not receive an additional award. Multiple reports describing the same underlying vulnerability are treated as one finding.
BotDigit may evaluate evidence of independent discovery when determining recognition-only awards (certificates and Hall of Fame acknowledgments).
Severity Is Not Self-Declared
Researchers select a preliminary severity rating during submission to assist initial triage.
However, the preliminary severity is not final. BotDigit's security team reassesses the final severity based on demonstrated exploitability, required attack prerequisites, realistic business impact, and affected assets.
Selecting "Critical" in the submission form does not automatically entitle the report to the Critical reward range.
In-Scope Targets
An endpoint being technically accessible does not automatically make every associated behavior eligible for a bounty.
botdigit.com— Primary Marketplace & Freelance Workspace Appbotdigit.com/api/v1/*— Backend Gateway Microservices & Auth EndpointsEscrow & Smart Contract APIs— Payment Transaction Verification & Release SystemsBotDigit Wallet APIs— Internal Ledger, Top-Up & Payout Handlers
Out-of-Scope & Prohibited Targets
- Admin infrastructure, internal staging databases, and production vault secrets
- Spam, phishing, social engineering, physical security, or credential stuffing
- DoS/DDoS attacks, volume-based fuzzing, or automated vulnerability scanner dumps
- Self-XSS (unless chained to actionable privilege escalation)
- Missing security headers or TLS cipher observations without a working exploit PoC
- Public disclosure before the 30-day responsible disclosure window has elapsed
Testing Standards & Prohibition of Degradation
Required Safe Testing Conduct
- •Use only researcher-owned test accounts for validation.
- •Execute minimal requests required to demonstrate technical proof of concept.
- •Immediately halt testing upon confirming vulnerability existence.
- •Handle any inadvertently accessed data with strict confidentiality.
Prohibited Testing Activities
- •Do not access, download, or inspect another user's private data beyond the absolute minimum required to prove the flaw.
- •Do not modify, corrupt, or delete production data or user records.
- •Do not transfer, escrow, or withdraw funds belonging to other users.
- •Do not perform destructive database queries or account lockouts.
- •Do not conduct high-volume traffic tests, stress tests, or automated scanner dumps.
- •Do not disrupt platform availability or cause service degradation.
- •Do not execute physical attacks, phishing, social engineering, or spam against BotDigit staff or users.
BotDigit Wallet Credit & Platform Perks (When Approved)
Financial TransparencyWhen an optional or discretionary Wallet Top-Up Credit is expressly granted, it is deposited into the researcher's BotDigit Wallet.
🛍️ Spend on Platform
Credits can be used immediately to fund freelancer contracts, escrow milestone deposits, or purchase digital products.
🏦 Payout / Withdrawal
Eligible wallet balances may be withdrawn to cryptocurrency (USDT/USDC) or bank accounts, subject to account KYC verification and standard network fees.
✨ 100% Fee-Exempt
Unlike freelance revenue which incurs a 10% platform fee, bug bounty rewards are 100% exempt from platform marketplace commissions.
Triage Lifecycle & 30-Day Confidentiality
Researchers must keep all vulnerability information strictly confidential while BotDigit investigates and deploys remediation. Researchers must not publicly disclose the vulnerability during the first 30 days following acknowledgment unless BotDigit provides express prior written authorization.
Submission
Researcher submits complete report with reproduction steps and PoC.
Acknowledgment
Security Desk provides tracking ID within target SLA (48h initial response).
Triage & Validation
Security engineers verify scope, reproducibility, impact, and duplicate status.
Decision
Finding is categorized as Valid + Reward Eligible, Valid + Recognition Only, Duplicate, Informational, Out of Scope, or Invalid.
Recognition & Remediation
Certificates and Hall of Fame honors are published, patches deployed, and any discretionary credit credited.
Requesting Reconsideration
Researchers may request formal reconsideration of severity assignments, duplicate determinations, reward eligibility, or recognition status by replying to their ticket email or contacting [email protected] with technical justification. Good-faith appeals and technical discussions are always welcomed.
Responsible Disclosure Program Terms & Researcher Conduct
Program TermsBy submitting a vulnerability disclosure report to BotDigit, security researchers agree to conduct themselves in good faith under the following terms:
1. Non-Coercion & Good Faith
Researchers must not threaten public disclosure to force payment, demand compensation outside the published program, or threaten users or personnel. Legitimate, good-faith technical questions and appeals regarding bounty decisions are explicitly welcomed and do not constitute coercion.
2. Confidentiality & Public Disclosure
Researchers must keep findings confidential during the initial 30-day investigation and patching window. Researchers must not knowingly publish false factual claims, fabricate proof of concept evidence, or impersonate BotDigit personnel.
3. Program Framework & Discretion
Published bounty ranges describe the program's reward framework. Submitting a report does not create an unconditional monetary debt. Final bounty amounts are determined following technical review of impact and exploitability.
4. Non-Retroactive Program Application
The applicable bounty rules are those published and accepted at the time the report is submitted. Future updates or modifications apply prospectively to reports submitted after updated terms become effective.
Submit a Security Report
You will receive a tracking reference ID. Our security desk targets an initial acknowledgment response within 48 hours target.
Questions regarding our security program? Contact our security desk directly at [email protected]