Pré-visualização beta — rumo à 1.0. Problemas?
Responsible disclosure

Bug Bounty

Find bugs, get rewards.

€1,000top payout
I have something to share
Paid within 2 business daysNo registration neededUp to €1,000 per report

What we are looking for

1
01

Client mail, phone numbers or service info

Any access to configuration or data that should not be reachable.

2
02

Arbitrary code execution

Running unauthorized code on our infrastructure or panels.

3
03

Critical actions on client VPS

Removal, reinstallation or any improper interaction with services and customers.

and other ways to access client data.

Program scope

Anything affecting the confidentiality, integrity or availability of our clients' data or our production systems is in scope.

In scope

  • fusiora.com and all production subdomains
  • Client area (my.fusiora.com) and admin panel
  • Public APIs (api.fusiora.com) and identity / SSO flows
  • Authentication, authorization and session management
  • VPS / bare-metal provisioning, billing and quota logic
  • Internet-facing infrastructure operated by Fusiora

Out of scope

  • Volumetric DoS / DDoS, brute force or load testing
  • Automated scanner output without a working proof of concept
  • Best-practice suggestions with no impact (e.g. missing headers, SPF/DMARC)
  • Vulnerabilities in third-party services we do not operate

Rules of engagement

Help us protect our clients by following these guidelines during your research.

Please do

  • Provide clear reproduction steps and a proof of concept
  • Test only against your own accounts and resources
  • Report issues as soon as you discover them
  • Limit data access to the minimum needed to demonstrate impact
  • Give us reasonable time to fix before disclosing

Please don't

  • Access, modify or delete other users' data
  • Launch DoS / DDoS attacks or send spam
  • Use automated scanning that degrades our services
  • Publicly disclose a vulnerability before it is fixed

Safe Harbor

We consider security research conducted in good faith and in line with this policy to be authorized. We will not take legal action against researchers who follow these rules. If you are unsure whether something is allowed, ask us first at info@fusiora.com.

Table of finds and rewards

Remote code execution (RCE)
Critical€400 – €1,000
Local file access and more
High€150 – €700
SQL injection
High€150 – €700
IDORs / disclosure of sensitive information / memory leaks
Medium€30 – €500
Non-critical backend bugs(only new bugs are paid)
Low€5 – €10
Other vulnerabilities found
Variesdepends on criticality

Payment

Payments are made after the discovery and verification of a vulnerability within two business days. The reward is credited to your Fusiora account bonus balance, from which up to 50% of the amount can be withdrawn.

Bank card

Visa, Mastercard and other major cards.

E-wallets

PayPal and other supported electronic wallets.

Cryptocurrency

BTC, USDT (TRC-20) and other major coins.

Legal entity transfer

Bank transfer to a registered company account.

Questions, answers

If you have not found the answer to your question, write to the support team

I have something to share
Usamos cookies

Usamos cookies para melhorar sua experiência, analisar o tráfego e personalizar o conteúdo.