In response to recent wind events, bulk ordering is now available. Thank you to everyone working these storms.
Skip to content
$0.00
0

Bug Bounty & Vulnerability Disclosure Policy

The Policy :

Effective date: August 12, 2025

We value security research and welcome reports that help us keep our users safe. This policy explains what’s in scope, how to test, how to report, what we pay, and your legal safe harbor if you follow the rules.


Quick Summary

  • Program type: Public, good‑faith research only

  • Assets in scope: sketchmyroof.com and *.sketchmyroof.com (see details below)

  • Contact: [email protected]

  • Acknowledgement: within 3 business days

  • Triage target: within 7 days

  • Fix targets (guidance): 30/60/90 days by severity

  • Disclosure window: Coordinated disclosure; no public posting until we confirm a fix or 90 days, whichever is first

  • Rewards: Based on severity, impact, and report quality (see table)

If you suspect data exposure, stop, capture minimal proof, and report immediately.


Scope

In scope:

  • Primary domain: https://sketchmyroof.com/

  • Subdomains we operate: *.sketchmyroof.com (examples: www, app, api, cdn)

  • First‑party mobile/web apps that connect only to our backends above

Out of scope:

  • Third‑party service providers (hosting, email, analytics, payments) unless explicitly stated

  • Corporate social media profiles

  • Marketing landing tools or form services hosted on other domains

  • Staging, demo, or sandbox environments not listed above

  • Any system where ownership by Sketch My Roof Inc cannot be verified

If unsure about an asset, contact [email protected] before testing.


Eligibility

You are eligible for recognition or bounty if you:

  • Follow this policy and applicable laws

  • Are the first to report the specific issue to us

  • Avoid privacy violations and service disruption

  • Do not access more data than needed to demonstrate the issue

  • Do not publicly disclose before remediation or the 90‑day window

Reports from individuals on sanctions lists or in embargoed regions will not be accepted.


Rules of Engagement (Good‑Faith Testing)

Allowed:

  • Creating test accounts

  • Automated scanning at low volume

  • Exploiting only to the extent needed to prove impact

  • Using your own accounts and data for testing

Not allowed:

  • No DDoS or stress testing

  • No social engineering (phishing, vishing, pretexting)

  • No physical access to offices or equipment

  • No malware or backdoors

  • No spam or marketing exploits

  • No tampering with or destroying data

  • No pivoting into third‑party or partner systems

If you find PII, credentials, or production data, stop immediately and report.


What to Report

High‑value findings:

  • Auth/account issues (IDOR, broken access control, privilege escalation)

  • SQLi, OS command injection, RCE

  • Stored and reflected XSS with real impact

  • CSRF with sensitive state change

  • SSRF that reaches internal services or metadata

  • Path traversal with sensitive file access

  • Logic flaws allowing unauthorized actions or data access

  • Significant misconfigurations (auth bypass, open cloud storage, default creds)

Out of scope examples:

  • Missing security headers without clear exploit

  • Clickjacking on non‑sensitive endpoints

  • SPF/DMARC/DKIM suggestions without spoof evidence

  • Issues requiring rooted/jailbroken devices only

  • Rate‑limit or brute force without realistic impact

  • Version disclosure, stack traces without exploit

  • CSRF on logout or non‑sensitive actions

  • Self‑XSS or unrealistic user input


Rewards (Guidance)

SeverityExample ImpactReward (USD)
CriticalRCE, auth bypass, full DB read, cloud account takeover$19
HighSignificant data access, privilege escalation, SSRF to sensitive assets$15
MediumSensitive data of a single user, stored XSS, CSRF with state change$10
LowBest‑practice gaps with limited impact$5

How to Report

Send reports to [email protected] with:

  1. Title and severity (your estimate)

  2. Affected asset/URL and endpoint(s)

  3. Step‑by‑step reproduction with clear payloads

  4. Impact: what can an attacker do and to whom

  5. Proof of concept (screenshots, short video, or minimal exploit code)

  6. Your environment (browser/OS/tool versions), test account if used

  7. Remediation suggestion (optional)


Response SLAs

  • Acknowledge within 3 business days

  • Triage within 7 days

  • Target fixes: Critical: 30 days, High: 60 days, Medium/Low: 90 days

  • Status updates every 14 days until closure


Legal Safe Harbor

We will not pursue legal action for good‑faith security research that follows this policy.


Data Handling & Privacy

  • Use test data where possible

  • If you encounter user data or secrets, stop, report, and delete any copies after we acknowledge receipt

  • Do not access more than necessary to show impact


Coordinated Disclosure

Do not publicly disclose details until we confirm a fix or 90 days pass, whichever is first.

Version History

  • v1.0 — August 12, 2025 — Initial public program


FAQ

Can I run automated scanners? Low‑volume only.

Can I brute‑force passwords? No.

Can I use real customer data? No.

Will you pay for duplicates? No.

When will I be paid? After validation and fix plan acceptance; typically within 30 days of triage.


Contact

Headquarters

2125 Biscayne Blvd, Ste 204 #13883, Miami, FL 33137

Our Email

[email protected]