ShipHero Bug Bounty Program | ShipHero

ShipHero Bug Bounty Program

Guidelines for Responsible Disclosure

Last updated on: September 4, 2024

Overview

At ShipHero, the security of our users data and communication is our top priority. We are committed to maintaining the highest standards of security and welcome contributions from security researchers to help us achieve this goal. Through our Bug Bounty Program, we encourage the responsible reporting of vulnerabilities in our systems.

We value the efforts of security researchers and offer rewards for valid, high-quality reports that help us improve our platform’s security. By participating in this program, you agree to abide by the rules and guidelines outlined below.

Scope

We are interested in vulnerabilities that impact the security of ShipHero’s core services and customer data. Below is a list of in-scope and out-of-scope assets and vulnerability types.

In-scope Assets

Out-of-Scope Assets

Theoretical vulnerabilities that require unlikely user interaction or circumstances. For example:

Theoretical vulnerabilities that do not demonstrate real-world security impact. For example:

Optional security hardening steps / Missing best practices. For example:

Vulnerabilities that may require hazardous testing. This type of testing must never be attempted unless explicitly authorized:

Reports related to WordPress vulnerabilities are also out of scope.

Rules of Engagement

To ensure a safe and productive environment for testing, please adhere to the following rules:

Allowed Actions

Prohibited Actions

We encourage clear, detailed, and actionable reports to help us quickly understand and resolve vulnerabilities.

Vulnerability Reporting

How to Submit a Report

Submit your findings here.

Required Information

Communication Guidelines

Validation Process

Reward Guidelines

We offer rewards for valid vulnerabilities based on their severity and impact. Below are the general rules and reward ranges for our program.

General Rules

Eligibility

Legal and Compliance

By participating in this program, you agree to the following terms:

Program Modifications

Tax Implications

Responsible Disclosure

Security of user data and communication is of utmost importance to ShipHero. In pursuit of the best possible security for our service, we welcome responsible disclosure of any vulnerability you find in ShipHero. Principles of responsible disclosure include, but are not limited to: