Catch us — get a reward.
Our own program. We accept two kinds of findings: classic vulnerabilities (track A) and refutations of our security report (track B). Payout tiers are shared for both; the reward is credited to your platform balance.
Where you can hunt.
In scope
- createyourvpn.com and api.createyourvpn.com
- your own storefront domains
- an explicitly designated test server
Out of scope
- partners' and end users' servers and data
- denial-of-service / stress testing
- social engineering, spam, phishing
- physical access
Active testing is allowed only on the preprod stand (pp.*), so the hunt never touches live partners or their users. Issues that also affect production still count — just reproduce them on the stand.
Payout tiers.
RCE; access to other servers or SSH keys; authorization bypass; refuting an SR claim about key storage
IDOR to others' data; XSS with session hijacking; refuting other SR claims
XSS with limited impact; internal information disclosure
best-practice notes; a missing header without an exploit
Short and honest.
- Run active tests only on the designated preprod stand (pp.*) — never against production, partner or user servers.
- The reward goes only to the first reporter; duplicates get a hall-of-fame credit.
- A reproducible proof of concept is required; 'you're missing header X' without an exploit is hall of fame, not a reward.
- Responsible disclosure: 90 days of silence; we respond within 72 hours.
- Safe harbor: we won't pursue good-faith research within scope.
- Test only on your own accounts.
- Out of scope: partners' and users' servers and data, denial of service, social engineering, spam, physical access.
Found something?
Send a report with a reproducible proof of concept by email. You can also find us through the security.txt file on our domains.