Bug Bounty


Overview
We (25Space) is currently not a member in a public listed bug bounty website/program. But sill we are offer rewards in relation about vulnerabilities.

How to report/get in touch
You can get in touch via our public contact [email protected] to request a membership to our bug bounty memberlist.

Play by the rules
Before attempting anything, reporting a security bug or joining our program, please be aware that testing our environment can be designated as a criminal act by the relevant authorities if you are violating German law or any other law. Please be aware that our rules do not supersede any applicable laws. However, we will not report you to the authorities if you abide by the rules provided—as long as we are not required to do so by applicable laws.
Furthermore, unannounced testing (load testing, attacks, etc.) can have a critical impact on our production infrastructure, please note that we do not accept this. However, we would like to state that we welcome the information about vulnerabilities and testing - as far as within the scope - is accepted.

Payments
All rewards will be granted at our discretion. Please note that in cases of the local legal TAX law we can't transfer this payment without official billing.

We offer temporary free cloud and infrastructure services, especially for minor issues and lower-rated security vulnerabilities/problems/reports (or similar). We will book this service for a specified account for a corresponding period (usually 1 year) free of charge.*
Example and offered services (at discretion and by agreement):
- MailAPI Basic - 1 year - free of charge.
- Online Cronjob - 1 year - free of charge.
- Certificate Checker - 1 year - free of charge.

*Individual agreement, no entitlement, only while stocks last and while products and services are available at that time. After the agreed term, products and services will automatically switch to the regular price at the publicly applicable price and service conditions at that time. The user accepts our terms and conditions of business and use.

Known reports
There are bugs or complaints that have already been reported to us (known internally or through bug bounty programs). Please understand that although we are still grateful for reports, we cannot honor them with further payments.
For security reasons, these are not published beforehand (not even superficially.