Report Security Issues
Found a vulnerability on boxbudy.us? Help us keep collectors safe. Hereโs how to report it responsibly โ and how our bounty program rewards you.
Please donโt: run denial-of-service tests, access other customersโ data, or publicly disclose an issue before weโve had a reasonable chance to fix it.
If you've found a security vulnerability on boxbudy.us, we want to hear about it. We review every legitimate report and work to fix confirmed issues quickly. Before reporting, please read this page โ including our fundamentals, bounty program, reward guidelines, and out-of-scope issues.
Fundamentals (Safe Harbor)
If you follow the principles below when researching and reporting a security issue, we will not pursue legal action or ask law enforcement to investigate you in response to your good-faith report. We ask that you:
- Give us reasonable time to investigate and fix the issue before disclosing it publicly or sharing it with others.
- Do not access or interact with accounts or data that aren't yours without the owner's consent โ use test accounts where possible.
- Make a good-faith effort to avoid privacy violations, service disruption, and data destruction.
- Do not exploit the issue beyond what is needed to confirm it, including to access sensitive data or demonstrate further risk.
- Comply with all applicable laws.
How to Report
Email your report to sales@boxbudy.us with the subject line "Security Report". Please send reports only through this channel rather than contacting individual team members. Include clear, reproducible steps โ reports we can't reproduce aren't eligible for a bounty.
Email a Security ReportBounty Program
We recognize and reward researchers who help keep boxbudy.us safe. Bounties are awarded at BoxBudy's discretion based on risk, impact, and report quality. To qualify, you must:
- Follow the Fundamentals above.
- Report a valid, reproducible vulnerability that poses a real risk to privacy or security.
- Submit your report by email as described in Section 02.
- Tell us about any accidental privacy violation or disruption that happened during testing.
- Understand that we prioritize reports by risk, so a response may take some time.
- Agree that we may publish reports after the issue has been fixed.
Rewards
Rewards are based on impact, exploitability, and report quality. The first valid report of an issue receives the bounty, and multiple bugs caused by a single underlying issue are treated as one report. Current maximum rewards by severity:
- Remote code execution
- Remote shell or command execution
- Vertical authentication bypass
- SQL injection that leaks targeted data
- Full account takeover
- Lateral authentication bypass
- Disclosure of sensitive internal data
- Stored XSS affecting other users
- Local file inclusion
- Insecure handling of authentication cookies
- Logic or business-process flaws
- Insecure direct object references
- Open redirects
- Reflected XSS
- Low-sensitivity information leaks
Out of Scope
The following are not eligible for a bounty:
Denial-of-service (DoS/DDoS) attacks, load testing, or automated scanning that degrades the site
Social engineering, phishing, or physical attacks against our team, customers, or partners
Vulnerabilities in third-party services we use (such as payment processors, hosting, or WordPress plugins) โ please report these to the vendor
Missing security headers, SPF/DKIM/DMARC settings, or clickjacking on pages without sensitive actions
Issues that require physical access to a user's device, or outdated browsers
Spam, rate-limiting, or "self-XSS" that only affects your own account
Contact Information
Security reports and questions about this policy can be sent to BOXBUDY LLC:
Security Reporting FAQ
Email sales@boxbudy.us with the subject "Security Report", including the affected URL, steps to reproduce, impact, and any proof of concept.
No โ if you follow our Fundamentals in good faith, we will not pursue legal action or ask law enforcement to investigate you because of your report.
Up to $200 for critical, $100 for high, and $50 for medium severity issues. Low-severity reports receive recognition. Final amounts depend on impact and report quality.
DoS attacks, social engineering, third-party service vulnerabilities, missing headers, self-XSS, and issues we canโt reproduce.
Only the first valid report of an issue receives the bounty.