Responsible Disclosure

Security Bounty Program

No technology is flawless. At cryptorobot.ai we are committed to ensuring that traders can manage their portfolios without worrying about the safety of their data or trade execution. If you discover something that could compromise the security of our users, we welcome your help — and we reward actionable reports.

What We Accept

Vulnerabilities In Scope

You may submit any number of vulnerability reports. Not every finding carries the same weight, however. If you identify a vulnerability in any of the following categories, please reach out to us immediately.

Qualifying Vulnerability Types

  • SQL Injection vulnerabilities
  • Encryption and cryptographic weaknesses
  • Remote Code Execution (RCE)
  • Authentication bypass or unauthorized data access
  • XML External Entity (XXE) attacks
  • Cloud storage misconfigurations (e.g. S3 bucket uploads)
  • Server-Side Request Forgery (SSRF)

Eligible Domains & Applications

The following properties are covered by this bounty program:

  • www.cryptorobot.ai
  • api.cryptorobot.ai
  • iOS application (Apple App Store)
  • Android application (Google Play Store)

Exclusions

Out of Scope

The following categories of issues are not eligible for rewards under this program:

  • Unlimited account creation without security impact
  • Actions available outside the UI with no identified security risk
  • Denial-of-service (DoS) attacks or service disruption
  • Attacks requiring man-in-the-middle or physical device access
  • Clickjacking, content spoofing, or text injection
  • CSV injection without demonstrated impact
  • Non-sensitive information disclosure (version numbers, stack traces, file paths)
  • Leaking tokens to trusted third parties over HTTPS
  • SSL/TLS, DNS, or HTTP header best-practice gaps without exploitable vulnerability
  • Missing action notifications without security impact
  • Known vulnerable libraries without a working proof of concept
  • Automated scanner or crash-dump reports without a working PoC
  • Unauthenticated, login, or logout CSRF
  • User enumeration or missing rate limiting
  • Vectors requiring unpatched software or outdated browsers (6+ months old)

Reporting

How to Submit a Vulnerability

Send your findings by email to security-bounty@cryptorobot.ai . Please describe the issue clearly and include the following:

  • 1A clear description of the vulnerability discovered
  • 2Step-by-step reproduction instructions
  • 3The full URL and any objects (filters, input fields) involved
  • 4Screenshots or screen recordings where applicable
  • 5Your IP address (kept confidential, used only to correlate testing activity in our logs)

Please be as detailed as possible — your report will be reviewed by our security specialists. Clear explanations and working proof-of-concept code significantly increase the likelihood of a reward.

Guidelines

Rules of Engagement

Please act responsibly and exercise extreme care throughout your investigation. Only use methods strictly necessary to identify or demonstrate a vulnerability.

  • Practice ethical hacking — always respect other users' privacy
  • Do not exploit discovered vulnerabilities beyond what is needed for your investigation
  • Do not share findings with third parties — give us reasonable time to resolve issues before any public disclosure
  • Do not use social engineering tactics to gain system access
  • Never install backdoors — they compromise system security regardless of intent
  • Do not modify or delete data — copy only the minimum needed and never go beyond a single record if that suffices
  • Only infiltrate systems when absolutely necessary, and never share access with others
  • Avoid brute-force techniques such as repeated password attempts
  • Ensure your own systems are secured to the highest standard

Compensation

Rewards

Our reward system is flexible — there is no fixed minimum or maximum. Bounties are determined by the severity of the vulnerability, its potential impact, and the quality of your report. To be eligible for a reward your country of residence must not appear on any applicable sanctions list.

Additional considerations:

  • For duplicate reports, only the earliest submission is rewarded
  • Multiple vulnerabilities stemming from a single root cause receive one bounty
  • Our team must be able to reproduce the issue from your report — vague submissions are not eligible
  • Reports with clear write-ups and working proof-of-concept code are far more likely to earn a reward

This is a discretionary program. cryptorobot.ai reserves the right to modify or discontinue it at any time. The decision to issue a reward is at our sole discretion.

FAQ

Frequently Asked Questions

Will I receive a reward for my findings?

We genuinely appreciate every effort to help us secure our platform. Whether a reward is issued depends on the severity and impact of the finding. Our team evaluates each submission individually and will communicate the outcome directly to you.

How long does review take?

We aim to acknowledge receipt within 48 hours and provide an initial assessment within two weeks. Complex issues may require additional time for our engineering team to investigate and remediate.

Can I disclose the vulnerability publicly?

We ask that you allow us a reasonable window to address the issue before any public disclosure. Coordinated disclosure protects our users and ensures the fix is deployed before details are made available.

Found Something?

Help us protect thousands of traders worldwide. If you have discovered a potential security issue, we want to hear from you.

Report a Vulnerability →