Report Security Issues | BoxBudy
Security ยท BOXBUDY LLC

Report Security Issues

Found a vulnerability on boxbudy.us? Help us keep collectors safe. Hereโ€™s how to report it responsibly โ€” and how our bounty program rewards you.

Last updated: October 9, 2026 About 4 min read
$200Maximum reward for critical issues
Safe harborFor good-faith research
Emailsales@boxbudy.us
FirstValid report wins the bounty

Please donโ€™t: run denial-of-service tests, access other customersโ€™ data, or publicly disclose an issue before weโ€™ve had a reasonable chance to fix it.

If you've found a security vulnerability on boxbudy.us, we want to hear about it. We review every legitimate report and work to fix confirmed issues quickly. Before reporting, please read this page โ€” including our fundamentals, bounty program, reward guidelines, and out-of-scope issues.

SECTION 01 ยท FUNDAMENTALS

Fundamentals (Safe Harbor)

If you follow the principles below when researching and reporting a security issue, we will not pursue legal action or ask law enforcement to investigate you in response to your good-faith report. We ask that you:

  • Give us reasonable time to investigate and fix the issue before disclosing it publicly or sharing it with others.
  • Do not access or interact with accounts or data that aren't yours without the owner's consent โ€” use test accounts where possible.
  • Make a good-faith effort to avoid privacy violations, service disruption, and data destruction.
  • Do not exploit the issue beyond what is needed to confirm it, including to access sensitive data or demonstrate further risk.
  • Comply with all applicable laws.
SECTION 02 ยท REPORT

How to Report

01Email usSend your report to sales@boxbudy.us
02Include detailsURL, steps to reproduce, impact, and proof
03We investigateWe confirm receipt and review by risk
04Fix & rewardEligible reports receive a bounty

Email your report to sales@boxbudy.us with the subject line "Security Report". Please send reports only through this channel rather than contacting individual team members. Include clear, reproducible steps โ€” reports we can't reproduce aren't eligible for a bounty.

Email a Security Report
SECTION 03 ยท ELIGIBILITY

Bounty Program

We recognize and reward researchers who help keep boxbudy.us safe. Bounties are awarded at BoxBudy's discretion based on risk, impact, and report quality. To qualify, you must:

  • Follow the Fundamentals above.
  • Report a valid, reproducible vulnerability that poses a real risk to privacy or security.
  • Submit your report by email as described in Section 02.
  • Tell us about any accidental privacy violation or disruption that happened during testing.
  • Understand that we prioritize reports by risk, so a response may take some time.
  • Agree that we may publish reports after the issue has been fixed.
SECTION 04 ยท REWARDS

Rewards

Rewards are based on impact, exploitability, and report quality. The first valid report of an issue receives the bounty, and multiple bugs caused by a single underlying issue are treated as one report. Current maximum rewards by severity:

Critical$200
Up to
  • Remote code execution
  • Remote shell or command execution
  • Vertical authentication bypass
  • SQL injection that leaks targeted data
  • Full account takeover
High$100
Up to
  • Lateral authentication bypass
  • Disclosure of sensitive internal data
  • Stored XSS affecting other users
  • Local file inclusion
  • Insecure handling of authentication cookies
Medium$50
Up to
  • Logic or business-process flaws
  • Insecure direct object references
LowRecognition
Thank-you & credit
  • Open redirects
  • Reflected XSS
  • Low-sensitivity information leaks
SECTION 05 ยท NON-REPORTABLE

Out of Scope

The following are not eligible for a bounty:

Denial-of-service (DoS/DDoS) attacks, load testing, or automated scanning that degrades the site

Social engineering, phishing, or physical attacks against our team, customers, or partners

Vulnerabilities in third-party services we use (such as payment processors, hosting, or WordPress plugins) โ€” please report these to the vendor

Missing security headers, SPF/DKIM/DMARC settings, or clickjacking on pages without sensitive actions

Issues that require physical access to a user's device, or outdated browsers

Spam, rate-limiting, or "self-XSS" that only affects your own account

SECTION 06 ยท CONTACT

Contact Information

Security reports and questions about this policy can be sent to BOXBUDY LLC:

Emailsales@boxbudy.us
Phone+1 (205) 745-5565
Business address1968 Carlson Rd, Parker, CO 80138, USA
Hours (CT)Monโ€“Fri 9 AM โ€“ 6 PM ยท Sat 10 AM โ€“ 4 PM ยท Sun closed
Quick answers

Security Reporting FAQ

Email sales@boxbudy.us with the subject "Security Report", including the affected URL, steps to reproduce, impact, and any proof of concept.

No โ€” if you follow our Fundamentals in good faith, we will not pursue legal action or ask law enforcement to investigate you because of your report.

Up to $200 for critical, $100 for high, and $50 for medium severity issues. Low-severity reports receive recognition. Final amounts depend on impact and report quality.

DoS attacks, social engineering, third-party service vulnerabilities, missing headers, self-XSS, and issues we canโ€™t reproduce.

Only the first valid report of an issue receives the bounty.