At Punchzee, security is our top priority. We appreciate the efforts of security researchers and ethical hackers who help us identify and mitigate potential security vulnerabilities. To encourage responsible disclosure, we have established a Vulnerability Disclosure and Reward Program.
This program applies only to software, services, and infrastructure owned and operated by Punchzee.
In Scope
Out of Scope
The following are not eligible for rewards:
If you discover a security vulnerability in software or services within the scope of this program, we encourage you to report it to us in a responsible manner. Please follow these guidelines:
We are committed to reviewing and addressing reported vulnerabilities as quickly as possible. We strive to acknowledge your report within a few days; however, depending on circumstances, it may take longer.
If you act in good faith, comply with this policy, test only systems within the program scope, avoid service disruption, protect user privacy, and promptly report any vulnerabilities you discover, Punchzee considers your security research to be authorized and will not initiate legal action against you for security research conducted in accordance with this policy.
If you inadvertently access sensitive data during testing, stop testing immediately, avoid copying, storing, or sharing the data beyond what is necessary to report the issue, and notify us without delay.
We offer rewards for valid security vulnerabilities based on their severity. Our reward amounts are determined using the Common Vulnerability Scoring System (CVSS) to ensure fairness and transparency:
Note: The final reward amount is at Punchzee's discretion and depends on factors such as impact, exploitability, and report quality. Rewards are not guaranteed and may be withheld for reports that are otherwise ineligible under this policy.
As we are still an early-stage company, our rewards are currently limited, but we may offer higher discretionary rewards for particularly valuable or critical reports.
Participants are responsible for ensuring that their participation complies with the laws and regulations of their jurisdiction.
Rewards are paid only after acceptance of a valid invoice issued through Stripe Invoicing or PayPal Invoicing with an online payment option. Participants must operate through a legally registered business or sole proprietorship authorized to issue such invoices. We reserve the right to request documentation verifying identity, business registration, and tax status before issuing any reward.
If a vulnerability has already been reported by another researcher, we follow a first-to-report policy. Only the first valid submission will be eligible for a reward. However, if multiple researchers provide significant additional insights or exploitation techniques that enhance our understanding of the issue, we may consider partial rewards at our discretion.
Punchzee reserves the right to modify or terminate this Vulnerability Disclosure and Reward Program at any time, without prior notice. Any changes will be updated on this page, and continued participation in the program constitutes acceptance of the updated terms.
To submit a vulnerability report, email us at security@punchzee.com with the subject line "Security Vulnerability Report." Please include:
We appreciate the efforts of security researchers in helping us maintain a safe and secure platform. Thank you for your contributions to Punchzee’s security!