Welcome to CloudCannon's bug bounty programme. If you believe you've found a critical vulnerability please follow the steps below and create a bug report. While we appreciate all submissions, only critical bugs are within scope.
Only the CloudCannon app (app.cloudcannon.com) is within scope. Other sub-domains will not be considered for bug bounties. At this stage we will only be assessing critical vulnerabilities.
CloudCannon will award valid reports based on the scope and severity of each report. Monetary rewards are paid by Wise Bank transactions only. Any charges incurred for Wise transactions will not be covered by CloudCannon. The rewards are as follows:
1. Check Scope
Confirm the bug fits within the scope defined in the Bug Bounty Policy
2. Submit Report
Submit your report which includes clear, concise and reproducible steps to replicate the issue.
The CloudCannon support team will make contact within five working days to acknowledge we have received your report.
4. Assessment & Rewards
CloudCannon will assess the report and will offer a reward based on severity and current scope. This may take several days of deliberation.
Only critical vulnerabilities that demonstrate complete compromise of the system’s integrity or confidentiality are eligible for a bounty. While we encourage you to submit all potential issues, lower severity issues are not in scope at this time.
It’s important to keep in mind that not all submissions will qualify for a bounty, and that the decision to award a bounty is entirely at the discretion of CloudCannon. CloudCannon have the final decision on which issues constitute security vulnerabilities.
While researching, we’d like to ask you to refrain from:
We do not cover TransferWise fees for international transactions, credit card transactions or any other services. TransferWise may deduct this from the amount sent to the payee.
Any activities conducted in a manner consistent with this policy will be considered authorised conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping to keep CloudCannon and our users safe!