Bug Bounty
25Space is currently not part of a public bug bounty platform. However, we welcome responsible disclosures and may
offer rewards at our discretion, depending on impact, quality of the report, and scope.
Send your report to [email protected].
If you want to be added to our security/bug bounty contact list, please mention this in your email.
Security testing can be illegal if it violates German law or any other applicable law. Our rules do not override any
laws. We will not intentionally pursue legal action against researchers who follow the rules below, act in good faith,
and do not cause harm, unless we are required to do so by applicable law.
Only vulnerabilities affecting 25Space-owned systems and services are eligible. Third-party services we do not control
may be out of scope. If you are unsure, include the affected hostname(s) and service name in your report.
We aim to acknowledge reports within a reasonable timeframe. Validation and remediation can take time depending on
severity and complexity. In many cases, a review window of up to 14-20 days is normal.
Any reward is voluntary and granted at our sole discretion. There is no entitlement to any payment or consideration.
Rewards depend on severity, exploitability, clarity, and novelty (not previously known/reported).
Where appropriate, we may offer free 25Space services instead of a cash payout, especially for low-severity findings.
Examples (subject to availability and agreement):
Cash rewards are typically considered in a broad range (e.g., USD 20 to USD 100) depending on the verified impact and scope.
Higher amounts are exceptional and require strong evidence of significant risk reduction.
Rewards are subject to legal and tax requirements. If local tax law requires an invoice or other documentation, we may
be unable to process a cash payment without it. Service credits, where offered, are provided for a defined period and
then automatically revert to regular pricing under the terms in effect at that time. Standard terms of business and use apply.
We may already be aware of certain issues (internally or via prior reports). Duplicate reports are appreciated, but
usually not eligible for additional rewards. For security reasons, we do not publish a public list of known issues.
Nothing on this page creates any contractual obligation. This program is a voluntary good-faith initiative by 25Space.
Responsible Disclosure / Bug Bounty
How to report
Safe harbor and rules
Scope
Out of scope (examples)
What to include in a report
Response timeline
Rewards / Payments
Duplicate / known issues
Legal note
