Bug Bounty
Find bugs, get rewards.
What we are looking for
Client mail, phone numbers or service info
Any access to configuration or data that should not be reachable.
Arbitrary code execution
Running unauthorized code on our infrastructure or panels.
Critical actions on client VPS
Removal, reinstallation or any improper interaction with services and customers.
and other ways to access client data.
Program scope
Anything affecting the confidentiality, integrity or availability of our clients' data or our production systems is in scope.
In scope
- fusiora.com and all production subdomains
- Client area (my.fusiora.com) and admin panel
- Public APIs (api.fusiora.com) and identity / SSO flows
- Authentication, authorization and session management
- VPS / bare-metal provisioning, billing and quota logic
- Internet-facing infrastructure operated by Fusiora
Out of scope
- Volumetric DoS / DDoS, brute force or load testing
- Automated scanner output without a working proof of concept
- Best-practice suggestions with no impact (e.g. missing headers, SPF/DMARC)
- Vulnerabilities in third-party services we do not operate
Rules of engagement
Help us protect our clients by following these guidelines during your research.
Please do
- Provide clear reproduction steps and a proof of concept
- Test only against your own accounts and resources
- Report issues as soon as you discover them
- Limit data access to the minimum needed to demonstrate impact
- Give us reasonable time to fix before disclosing
Please don't
- Access, modify or delete other users' data
- Launch DoS / DDoS attacks or send spam
- Use automated scanning that degrades our services
- Publicly disclose a vulnerability before it is fixed
Safe Harbor
We consider security research conducted in good faith and in line with this policy to be authorized. We will not take legal action against researchers who follow these rules. If you are unsure whether something is allowed, ask us first at info@fusiora.com.
Table of finds and rewards
Payment
Payments are made after the discovery and verification of a vulnerability within two business days. The reward is credited to your Fusiora account bonus balance, from which up to 50% of the amount can be withdrawn.
Bank card
Visa, Mastercard and other major cards.
E-wallets
PayPal and other supported electronic wallets.
Cryptocurrency
BTC, USDT (TRC-20) and other major coins.
Legal entity transfer
Bank transfer to a registered company account.
Questions, answers
If you have not found the answer to your question, write to the support team
I have something to share