Reporting Vulnerabilities to Changelog
Found a vulnerability in our systems? Fill out this form here. You'll hear back from us within two weeks at the absolute latest, and we'll let you know:
  • If it's been reported previously,
  • Whether or not we think it's a valid issue,
  • And if it's eligible for a reward.
Security Guidelines and Etiquette
Please read and follow these guidelines prior to sending in any reports.
  1. Do not test vulnerabilities in public. We ask that you do not attempt any vulnerabilities, rate-limiting tests, exploits, or any other security/bug-related findings if it will impact another community member. This means you should not leave comments on someone else’s tasks and questions, or otherwise, impact their experience on the platform.
  2. Do not report similar issues or variations of the same issue in different reports. Please report any similar issues in a single report. It's better for both parties to have this information in one place where we can evaluate it all together. Please note any and all areas where your vulnerability might be relevant. You will not be penalized or receive a lower reward for streamlining your report in one place vs. spreading it across different areas.
  3. The following domains are not eligible for our bounty program as they are hosted by or built on external services:
    We've listed the service provider of each of these domains so that you might contact them if you wish to report the vulnerability you found.
  4. DoS (Denial of Service) vulnerabilities should not be tested for more than a span of 5 minutes. Be courteous and reasonable when testing any endpoints on as this may interfere with our monitoring. If we discover that you are testing DoS disruptively for prolonged periods of time, we may restrict your award, block your IP address, or remove your eligibility to participate in the program.
  5. Please be patient with us after sending in your report. We’d appreciate it if you avoid messaging us to ask about the status of your report. Our team will get back to you as quickly as we are able. It is okay to inquire about the status of your report if you haven’t heard from us 2 weeks after sending it in. Otherwise, we ask that you please wait patiently for us to contact you, unless you have more information relevant to the vulnerability that you’d like to share.
Vulnerability Assessment and Reward
Vulnerabilities are assessed via BugCrowd's taxonomy rating and our judgment. For now we provide you lifetime Changelog membership for free!