Bug Bounty Program
The security of our users and partners is a priority. Therefore, we created this Bug Bounty program to encourage the community of researchers to identify and report vulnerabilities in our services, ensuring continuous improvements.
1. Scope
- In scope: services under bytemax.exchange (website, API and official subdomains).
- Out of scope: third-party services, external integrations and vendors not controlled by ByteMax.
- Non-destructive testing only: no DoS/DDoS, spam, brute-force, user-impacting exploitation or service degradation.
2. Responsible Disclosure Rules
We ask researchers to maintain the confidentiality of discoveries until we can fix the flaw. It is prohibited to:
- Access, modify, or destroy other users' data.
- Execute attacks that cause significant service unavailability.
- Exploit the vulnerability for undue advantage or profit.
By following the rules, we offer Safe Harbor, with no legal measures or account suspensions related to authorized tests.
3. Reporting Vulnerabilities
4. Simplified Classification
We use four main levels to determine severity:
- Low: Minor issues or limited impact (e.g., simple reflected XSS).
- Medium: Partial unauthorized access or stored XSS with specific conditions.
- High: Sensitive data leakage, dangerous injections.
- Critical: Remote code execution, full server access, or massive data leakage.
5. Simplified Reward Calculation
After validating the vulnerability, we assign a severity (Low, Medium, High, or Critical) and apply the reward values below:
| Severity | Payment Range |
|---|---|
| Low | R$ 200 - R$ 500 |
| Medium | R$ 800 - R$ 1,500 |
| High | R$ 2,000 - R$ 5,000 |
| Critical | Above R$ 10,000 |
The final value within each range may vary according to the exploit's complexity, originality, real risk, and quality of the submitted documentation.
6. Internal Process
- Send your report to [email protected] with a brief impact summary.
- Include reproduction steps, evidence (logs, screenshots) and, if possible, a non-destructive PoC.
- Wait for acknowledgment and work with us to validate and remediate the issue.
- Keep the report confidential and do not disclose publicly before a fix and alignment with our team.
7. Contributing Researchers
We thank the researchers who have responsibly contributed to ByteMax's security:
- Igor Pascal
- Pedro Rodiguero
