At Prop Firm Match, we're committed to keeping our platform secure and private for every trader who uses it. Our Bug Bounty Program invites ethical hackers and security researchers to responsibly report vulnerabilities, helping us safeguard the community before issues can be exploited. This article covers how the program works, what's in and out of scope, and what you can expect if you submit a report.
Why Participate
Reporting a valid vulnerability comes with a few benefits:
Protect the Community: Help make the platform safer for every trader who uses it.
Earn Your Spot: Gain public recognition in our Hall of Fame.
Get Rewarded: Score exclusive Prop Firm Match swag and, in rare cases, monetary rewards for critical findings.
Program Rules
To keep the program ethical and productive, a few ground rules apply:
Be the first to report the issue.
Focus only on in-scope assets owned by Prop Firm Match.
Never access, modify, or store user data.
Don't disclose the issue publicly before we've closed the report.
Use automated tools responsibly.
Always comply with applicable laws.
Engagement Guidelines
When testing, your research needs to prioritize safety and respect for the platform and its users:
Use test accounts only.
Don't exploit a vulnerability beyond what's necessary to demonstrate it.
Avoid DoS, brute-force, or spam attacks.
No phishing or social engineering, especially targeting our staff.
Recognition and Rewards
Every valid report is appreciated, and we recognize contributions in a few ways: public credit in our Hall of Fame, exclusive Prop Firm Match swag for impactful submissions, and discretionary monetary rewards for rare, critical vulnerabilities. Reward decisions are final and based on severity, reproducibility, and the overall quality of the report.
What to Expect (Our SLA)
We aim to keep communication clear and timely throughout the process:
First Response: Within 2 business days.
Time to Triage: Within 10 business days.
Time to Recognition: Within 14 business days.
Time to Resolution: Varies based on the complexity and severity of the issue.
What's Out of Scope
Some issues aren't eligible for rewards or recognition, including:
Issues that require physical access.
Vulnerabilities involving outdated or unpatched browsers.
Cosmetic UI issues, like misalignments.
Clickjacking on non-sensitive or static pages.
Missing headers without demonstrated exploitability.
Vulnerabilities in third-party software.
Rate limit or caching glitches, such as view or like counts.
CSRF without a proven exploit.
Broken links or redirects without a security impact.
Unvalidated automated tool reports.
Legal Notice
By participating, you agree to comply with all local, national, and international laws, and you're responsible for any taxes owed on rewards you receive. Prop Firm Match may modify or terminate this program at any time, and any changes will not apply retroactively.
Disclosure Policy
Informative reports are not publicly disclosed. With your permission, high-impact discoveries may be featured in community updates or blog posts to help others understand the kind of research that keeps the platform secure.
If you've found a vulnerability, you can submit it directly through the Submit a Bug button on the Bug Bounty Program page. If you have questions about the program before submitting, reach out to our team via Live Chat or at [email protected].
