Bug Bounty & Vulnerability Disclosure Policy
The Policy :
Effective date: August 12, 2025
We value security research and welcome reports that help us keep our users safe. This policy explains what’s in scope, how to test, how to report, what we pay, and your legal safe harbor if you follow the rules.
Quick Summary
Program type: Public, good‑faith research only
Assets in scope:
sketchmyroof.comand*.sketchmyroof.com(see details below)Contact: [email protected]
Acknowledgement: within 3 business days
Triage target: within 7 days
Fix targets (guidance): 30/60/90 days by severity
Disclosure window: Coordinated disclosure; no public posting until we confirm a fix or 90 days, whichever is first
Rewards: Based on severity, impact, and report quality (see table)
If you suspect data exposure, stop, capture minimal proof, and report immediately.
Scope
In scope:
Primary domain:
https://sketchmyroof.com/Subdomains we operate:
*.sketchmyroof.com(examples:www,app,api,cdn)First‑party mobile/web apps that connect only to our backends above
Out of scope:
Third‑party service providers (hosting, email, analytics, payments) unless explicitly stated
Corporate social media profiles
Marketing landing tools or form services hosted on other domains
Staging, demo, or sandbox environments not listed above
Any system where ownership by Sketch My Roof Inc cannot be verified
If unsure about an asset, contact [email protected] before testing.
Eligibility
You are eligible for recognition or bounty if you:
Follow this policy and applicable laws
Are the first to report the specific issue to us
Avoid privacy violations and service disruption
Do not access more data than needed to demonstrate the issue
Do not publicly disclose before remediation or the 90‑day window
Reports from individuals on sanctions lists or in embargoed regions will not be accepted.
Rules of Engagement (Good‑Faith Testing)
Allowed:
Creating test accounts
Automated scanning at low volume
Exploiting only to the extent needed to prove impact
Using your own accounts and data for testing
Not allowed:
No DDoS or stress testing
No social engineering (phishing, vishing, pretexting)
No physical access to offices or equipment
No malware or backdoors
No spam or marketing exploits
No tampering with or destroying data
No pivoting into third‑party or partner systems
If you find PII, credentials, or production data, stop immediately and report.
What to Report
High‑value findings:
Auth/account issues (IDOR, broken access control, privilege escalation)
SQLi, OS command injection, RCE
Stored and reflected XSS with real impact
CSRF with sensitive state change
SSRF that reaches internal services or metadata
Path traversal with sensitive file access
Logic flaws allowing unauthorized actions or data access
Significant misconfigurations (auth bypass, open cloud storage, default creds)
Out of scope examples:
Missing security headers without clear exploit
Clickjacking on non‑sensitive endpoints
SPF/DMARC/DKIM suggestions without spoof evidence
Issues requiring rooted/jailbroken devices only
Rate‑limit or brute force without realistic impact
Version disclosure, stack traces without exploit
CSRF on logout or non‑sensitive actions
Self‑XSS or unrealistic user input
Rewards (Guidance)
| Severity | Example Impact | Reward (USD) |
|---|---|---|
| Critical | RCE, auth bypass, full DB read, cloud account takeover | $19 |
| High | Significant data access, privilege escalation, SSRF to sensitive assets | $15 |
| Medium | Sensitive data of a single user, stored XSS, CSRF with state change | $10 |
| Low | Best‑practice gaps with limited impact | $5 |
How to Report
Send reports to [email protected] with:
Title and severity (your estimate)
Affected asset/URL and endpoint(s)
Step‑by‑step reproduction with clear payloads
Impact: what can an attacker do and to whom
Proof of concept (screenshots, short video, or minimal exploit code)
Your environment (browser/OS/tool versions), test account if used
Remediation suggestion (optional)
Response SLAs
Acknowledge within 3 business days
Triage within 7 days
Target fixes: Critical: 30 days, High: 60 days, Medium/Low: 90 days
Status updates every 14 days until closure
Legal Safe Harbor
We will not pursue legal action for good‑faith security research that follows this policy.
Data Handling & Privacy
Use test data where possible
If you encounter user data or secrets, stop, report, and delete any copies after we acknowledge receipt
Do not access more than necessary to show impact
Coordinated Disclosure
Do not publicly disclose details until we confirm a fix or 90 days pass, whichever is first.
Version History
v1.0 — August 12, 2025 — Initial public program
FAQ
Can I run automated scanners? Low‑volume only.
Can I brute‑force passwords? No.
Can I use real customer data? No.
Will you pay for duplicates? No.
When will I be paid? After validation and fix plan acceptance; typically within 30 days of triage.
Contact
Email: [email protected]
Emergency: Use the subject line [URGENT] for priority response
Headquarters
2125 Biscayne Blvd, Ste 204 #13883, Miami, FL 33137