We value security researchers and reward those who help us improve our security posture.
Send security reports to: privacy@pipeboard.co
Example: Complete authentication bypass allowing access to any user account
Example: Information disclosure vulnerability (October 2025, $100)
Example: Open redirect that could be used in phishing attacks
Example: Authentication security gap (October 2025, $40)
Acknowledge receipt, assign tracking number, set expectations
Reproduce vulnerability, assess severity, determine bounty eligibility
Develop and test fix, document issue and solution, deploy
Notify researcher, confirm reward, process payment within 5 business days
October 2025
Severity: High - Privacy violation affecting all users
Impact: Could enable targeted attacks against users
Why $100: High exploitability, professional report, substantial fix required, affects all users
October 2025
Severity: Low - Defense-in-depth violation
Impact: Limited exploitability, narrow time window required
Why $40: Valid security concern but low real-world exploitability
Yes, but please be careful and minimize impact. Don't access real user data, don't perform actions that affect other users, and stop testing once you've confirmed the vulnerability.
First valid report gets the bounty. We'll let you know if it's a duplicate.
Within 5 business days after the fix is deployed and we've confirmed your PayPal address.
Yes, but please wait until we've fixed it and coordinate timing with us. We typically ask for 90 days.
Yes, absolutely. We can process payments and keep your identity confidential if you prefer.
We're grateful to the following security researchers who have helped make Pipeboard more secure:
Want to join our Hall of Fame? Report a valid security vulnerability and help protect our users!
Send your security findings to our dedicated security team
Report Security IssueLast Updated: March 18, 2026