Our number one priority is the security of the SendSafely platform. The bug bounty program rewards researchers for discovering and reporting vulnerabilities that present a high risk to the overall security of our platform and our users.
The SendSafely program follows a set of well defined and industry standard disclosure terms and vulnerability rating taxonomies.
To avoid confusion, SendSafely will rate all submissions using the Bugcrowd Vulnerability Rating Taxonomy.
Each submission will be evaluated by the SendSafely security team on the basis of first-to-find. You will qualify for a reward if you were the first person to alert us of a previously unknown issue and the issue triggers us to make a code or configuration change to our platform.
Our Bug Bounty program pays cash rewards issues with a Technical Severity of P1, P2 and P3. Issues rated P4 or lower may be submitted, but will not likely be eligible for a cash reward. Our standard payout policy is below.
We ask that you please abide by the following rules when participating in the SendSafely bug bounty program:
All URLs hosted under www.sendsafely.com are included within the scope of our bug bounty program. Please keep in mind that this is a production environment.
When performing your testing, we ask that you:
Please also note that the following findings are specifically excluded from the bounty:
To obtain a test account, sign up for a free SendSafely Pro Trial. Once you complete the registration process, you will have full access to all of the features included in our PRO plan for 14 days.
All submissions must be made using our Security Bug Reporting Form. You'll be expected to explain where the bug is, who it affects, how to reproduce it, the parameters it affects, and any PoC code.
You can also upload any files that you may have that proves the vulnerability exists. You want to add as much information as you can to help reproduce the vulnerability. This not only helps the company quickly reproduce the issue but also helps moves your submission through the review process a lot faster.
The following information will be required for all valid bug submissions.
Questions? Send an email to support@sendsafely.com.
Every file that moves through SendSafely is encrypted on the sender's device with OpenPGP/AES. The platform sees ciphertext only, which is why researcher findings against the encryption boundary matter.
Audited annually under SOC 2 Type 2. We disclose findings responsibly and pay researchers who help us stay that way.
Submit through the SendSafely Security Bug Reporting Form so your proof-of-concept files and reproduction steps reach our security team encrypted end-to-end.