AngelTrack pays cash bounties for security-related bugs found in the application.
If you find a security-related bug in the AngelTrack product, please call us and claim your reward.
Program Definition
AngelTrack LLC wishes to reward white-hat security researches for their efforts, and encourage responsible disclosure of vulnerabilities.
To that end, AngelTrack LLC pays a bounty for any security-related bugs or vulnerabilities reported to its headquarters, in the reasonable and customary manner for our industry.
The amount of the bounty paid for each confirmed report is subject to the sole discretion of AngelTrack LLC, but will in all cases be at least $100, and not more than $25,000.
If you discover a minor denial-of-service risk, for example the WordPress wpcron.php denial-of-service exposure, we will pay half the normal bounty.
No bounty will be paid for issues already reported by others, even if not yet fixed.
NO QUESTIONS ASKED. We will pay a bounty to anyone who responsibly reports a security issue to us.
Priorities
Our security focus is on the main AngelTrack product, located here:
A secondary priority is our public WordPress site, located here:
The lowest priority is our public training site, located here:
Limitations
Our public website and our training website are not part of our product, instead they are just freestanding WordPress sites which contain little of value. If you find a bug in our public website or in our training website, we will still pay a bounty for it, but the stakes are low and so the bounty will reflect that. Your reward might just be an extra hour in the ball pit. That said, we have in the past paid as much as $200 for the discovery of a buggy plugin, so if you find something compelling then please call.
Before you begin any tests against our training website, contact us first. It has already been through multiple security reviews already, and we have accepted certain security compromises in order to keep it free and open to the public, and so we don't want you wasting your time re-reporting these compromises.
Before you begin any tests against our production cluster, call us first. Depending on your plans, we may require you to perform the tests during our scheduled maintenance window, or at least on a Sunday. In any case we want to know when you'll be working so that we can monitor things from our end to augment any discoveries you make. You will still get full credit for any issue that we find as a consequence of your efforts.
No AI submissions. The false-positive / hallucination rate is now too high. We will only work with humans.
US Citizens Only
For non-critical issues, we accept and pay for security research only from US citizens living within the United States of America. Previously we welcomed reports from all comers, but the barrage of trivial reports from India has compelled us to close the program to foreigners.
For critical issues, we accept reports from any party, from any nation, no questions asked, and will compensate you by anonymous means if you wish.
Customer-Specific Versus Product-Wide Issues
Each one of our customers has separate user accounts, and separate security settings which they control. It is possible to find a security problem with one particular customer's deployment, which does not affect all other AngelTrack customers. We still want to hear about these problems if you find them, but if the problem is not the fault of AngelTrack LLC, then we will refer the matter to the customer's IT department to be addressed, and we will recommend to them that they pay you a bounty, however we do not guarantee that they will do so.
Subdomains
Many AngelTrack customers have their own subdomains. A subdomain allows the customer to restyle their login page, and provides disambiguation so that their employees need not specify which state they are in, nor wonder whether they've logged-in to the correct database if they have accounts at multiple providers. However, AngelTrack subdomains are just front-end veneers; all non-trivial requests are still handled by the main product residing at app.angeltrack.com.
This is the Only Bounty Program for AngelTrack
The aforementioned is the only bug bounty program offered by AngelTrack LLC.
We previously had a posting on OpenBugBounty, but got flooded with trivial and duplicate requests about our WordPress site, and so we had to discontinue the listing.
Hall of Fame
We maintain a Hall of Fame for whitehat hackers who provide valuable assistance in securing our infrastructure.
AngelTrack Security Hall of Fame
