Aegis Web Security and Bug Hunting The program
We provide direct cash rewards to the first researchers who find and responsibly report a critical or verifiable security vulnerability in our Aegis web infrastructure (betterwithaegis.com) and API services.
In-Scope
Technical vulnerabilities in the following areas are within the scope of the reward:
- https://betterwithaegis.com all web pages and session mechanisms on it
- /api/* endpoints (Privilege escalation, IDOR, SQLi, SSRF, RCE, etc.)
- Session and Cookie Security: HMAC manipulation, token leakage, or founder privilege spoofing
- Sensitive Data Exposure: Server environment variables, secret keys, or PII leakage
Out-of-Scope
The following actions and situations are out of scope for the bug bounty:
- DDoS & Denial of Service: Flood attacks aimed at slowing down or crashing servers
- Social Engineering & Phishing: Phishing attempts targeting developers or users
- External Infrastructure Errors: General outages of Cloudflare, Discord, or hosting provider
- Destructive Actions: Deleting or corrupting user data (PoC is sufficient to show)
Responsible Disclosure and Reward Rules
Report Vulnerability
Fill out the form below to test and report the vulnerability.
Report directly via Discord
Faster communication and instant chat
Instead of filling out a form, you can report the vulnerability by coming directly to our official Aegis Discord server and opening a private support ticket or by messaging our founders.
Rewards are transferred to the reported account within 24 hours at the latest after the vulnerability is verified and confirmed to be patched in our systems. In case of multiple reports of the same vulnerability, only the first report is considered.