Security Bounty Program

At ImprovMX, the security of our users’ data is a priority. We build our software and infrastructure with this goal in mind. That’s why we decided to welcome your help through our bounty program to put our security to the test!

To take advantage of it, you’ll need to follow a few guidelines:

What we’re looking for

We’re looking for any security exploit. But we’ll be extra generous with:

Please keep in mind this bounty program doesn’t concern regular bugs in our application, but only security flaws allowing intruders to gain access to data of other users. If you wish to report a regular bug, contact support@improvmx.com.

Examples of Non-Qualifying exploits

Some exploits are excluded from our compensation scheme, including:

Examples of Non-Qualifying reports

These are theoretical vulnerabilities we’re aware of, but we decided they didn’t present any risk in our case:

Rewards

Our reward system is flexible and doesn’t have any strict upper or lower limit. This means particularly creative or severe bugs will be rewarded accordingly. The amount will exclusively depend on the severity of the vulnerability.

Rewards will be sent using Paypal once the vulnerability has been fixed. These services collect a fee for processing the transaction, which gets deducted from the amount awarded. Please note that you are responsible for paying the proper amount of taxes in your country on the amount you are getting compensated.

Report submission

Please submit your report using our dedicated form. We answer all submissions within a few days. Once the patch is online, we’ll pay your bounty using PayPal.

If you have any questions regarding the program, please contact us at security@improvmx.com.