Dashten

Security · Responsible Disclosure

Bug Bounty Program

We invite security researchers to responsibly identify and report vulnerabilities in Dashten. Qualifying reports — Medium severity and above, with a complete proof of concept — are eligible for a monetary reward.

Scope
dashten.net
Rewards
$50 – $250
Accepted severity
Medium · High · Critical
Submit to
[email protected]

01 — Rewards

Reward ranges by severity

Reward amounts are determined by validated severity, exploitability, and real-world impact, at our discretion. Only the first reporter of a unique, reproducible issue is eligible.

SeverityReward (USD)Representative examples
Critical $200 – $250 Remote code execution, authentication bypass, SQL injection exposing other users' data, or account takeover affecting arbitrary users.
High $100 – $200 Stored XSS affecting other users, IDOR exposing or modifying another user's data, or privilege escalation.
Medium $50 – $100 CSRF on a sensitive action with real impact, reflected XSS with limited interaction, or a meaningful access-control flaw.
Low / Informational Not eligible Appreciated and acknowledged, but not rewarded.

02 — Scope

In scope: the website only

In scope

dashten.net

The public web application and its endpoints on this domain.

Out of scope

Anything not hosted on dashten.net — third-party services, subprocessors, vendor infrastructure, and any other domain or subdomain. See the full exclusion list in section 04.

03 — Reporting

How to submit a report

Email is the only accepted channel. Reports submitted by any other means will not be considered for a reward.

Send to [email protected]
A complete proof of concept is mandatory. Reports without step-by-step, reproducible proof will be rejected. Each report must include:
  1. Title & location

    A clear title and the affected URL(s) / endpoint(s) on dashten.net.

  2. Vulnerability type & severity

    The vulnerability class and your assessed severity.

  3. Step-by-step reproduction

    Numbered instructions we can follow from scratch, with a working PoC — request/response, payload, script, screenshots, or a short video.

  4. Impact & preconditions

    The realistic security impact, plus any test accounts, tokens, or preconditions used.

04 — Exclusions

Out of scope

The following are not eligible for a reward (illustrative, not exhaustive):

  • Denial of service (DoS/DDoS) and resource-exhaustion attacks
  • Rate-limiting or brute-force concerns without a real security impact
  • Missing security headers or cookie flags without a working exploit
  • Self-XSS, or issues requiring the victim to run attacker code
  • Clickjacking on pages with no sensitive state-changing action
  • Login/logout/email-confirmation CSRF, or CSRF on non-sensitive actions
  • Social engineering, phishing, or physical attacks
  • SPF / DKIM / DMARC configuration or email spoofing
  • Automated scanner output or theoretical reports without a PoC
  • Best-practice or informational notes with no exploitable impact
  • Version banners, public information, or verbose errors without impact
  • Issues requiring a rooted device, physical access, or a MITM position
  • Outdated libraries without a demonstrated working exploit
  • Content spoofing or text injection without an attack vector
  • Anything hosted outside dashten.net

05 — Rules of engagement

Test safely and legally

  • Only test against accounts you own or are permitted to use.
  • Never access, modify, delete, or exfiltrate other users' data — if you can reach it, stop and report.
  • Avoid privacy violations, service degradation, and data destruction.
  • Do not run disruptive automated scanners against the platform.
  • Keep issues confidential and allow reasonable time to remediate before any disclosure.
  • Comply with all applicable laws.

Safe harbor

Good-faith research that follows these rules is considered authorized. We will not pursue legal action for it and will work with you to resolve the issue. Violating these rules voids eligibility and safe harbor.

Eligibility

In scope · Medium severity or higher · reproducible from your PoC · not already known · first reporter · within these rules and the law. Validity, severity, and reward amount are determined at our discretion; decisions are final.

Report a vulnerability

All reports and questions go to our security team.

[email protected]

Last updated July 28, 2026