Security Acknowledgments

Researchers who reported issues to us. The bug-bounty pool is 3% of revenue; payouts flow once revenue exists.

Severity → payout

SeverityDescriptionPayout (USD)
CriticalRemote code execution, persistent auth bypass, full account takeover$500
HighSignificant data exposure, privilege escalation to Pro without payment$200
MediumCross-origin data leakage, denial-of-service affecting other users$75
LowInformation disclosure that doesn't compromise other users$25
InfoA non-exploitable finding that still helps us improve$10

Pool status

Current pool balance: $0 (no revenue yet; pool activates when revenue exists).

The pool accrues at 3% of revenue until spent. The ledger is /state/bounty-pool/ledger.jsonl on our side; we publish the total here monthly. The critic-agent (configurable daily review at 07:55) generates internal "researcher" findings that go into the same pool accounting for transparency.

Researchers

No external disclosures yet. When the first finding arrives, it will be acknowledged here within 7 days of triage.

How to report

Disclosure policy

Scope

What we won't do