We value security researchers and reward those who help us improve our security posture.
Each report is assessed against the version of these terms — scope, exclusions and reward bands — that was published on the date we received it. If we change the programme later, the change does not apply retroactively to reports already with us.
Send security reports to: privacy@pipeboard.co
The bands below are set by severity. Where your report lands inside a band also depends on its quality — a clear write-up with accurate root-cause analysis and reproduction steps we can follow is worth more than the same finding reported vaguely. Severity is assessed on the impact we can confirm, not the impact claimed.
Example: Complete authentication bypass allowing access to any user account
Example: Information disclosure vulnerability affecting all users
Example: Open redirect that could be used in phishing attacks
Example: Authentication gap with limited real-world exploitability
We confirm we received your report, log it, and tell you what happens next
Our security team reviews the report against our source code to confirm the finding, assess severity and determine bounty eligibility. This assessment sets the reward tier. We tell you the outcome, and pass confirmed findings to engineering
Engineering schedules the fix by severity alongside its other priorities, so we do not commit to a date. We keep you informed as the status changes
Once the fix is live we confirm the reward and process payment within 15 business days of agreeing your payment details
October 2025
Severity: High - Privacy violation affecting all users
Impact: Could enable targeted attacks against users
Why it rated High: High exploitability, professional report, substantial fix required, affects all users
October 2025
Severity: Low - Defense-in-depth violation
Impact: Limited exploitability, narrow time window required
Why it rated Low: Valid security concern but low real-world exploitability
August 2026 — $300
Severity: High - Weakness in the CSRF control protecting every ad-platform connection
Impact: Could allow a connection to be linked to the wrong account
Why it rated High: Affected all platform connectors, cleanly reproduced, and the report was scrupulous about separating what was demonstrated from what was inferred - which raised its quality score rather than lowering it
Sign up for a free account at https://pipeboard.co/signup. Testing is done from the same access any regular user has. We do not grant special test environments, staging access, or privileged credentials.
Yes, but please be careful and minimize impact. Don't access real user data, don't perform actions that affect other users, and stop testing once you've confirmed the vulnerability.
First valid report gets the bounty. We'll let you know if it's a duplicate.
Payment follows the fix: once it is deployed to production and we have agreed your payment details, we process the reward within 15 business days. We do not pay before a fix is live.
No. The reward is the gross amount we send in USD via PayPal. Any receiving fee or conversion cost on your side comes out of that figure - we already absorb an exchange-rate spread on the paying side, so we don't gross rewards up.
Yes, but please wait until we've fixed it and coordinate timing with us. We typically ask for 90 days.
Yes, absolutely. We can process payments and keep your identity confidential if you prefer.
We're grateful to the following security researchers who have helped make Pipeboard more secure:
Want to join our Hall of Fame? Report a valid security vulnerability and help protect our users!
Send your security findings to our dedicated security team
Report Security IssueLast Updated: March 18, 2026