Bug bounty program
Help us keep Pachca.com secure. We welcome security researchers and pay rewards for the vulnerabilities they find.
Report a vulnerabilityParticipation rules
- Only previously unknown vulnerabilities that Pachca's security team can fully reproduce are eligible
- Research must be done in good faith, which means strictly following the program rules and any other terms posted on the asset you're testing
- Vulnerabilities you find must not be used for illegal or malicious purposes
- Reports submitted by current or former employees are treated as informational
Testing rules
- Test only with your own accounts or with accounts whose owners have explicitly agreed to it
- Limit scanning tools to 3 requests per second. If you notice the service degrading even within this limit, stop scanning
- To keep your traffic from being flagged as malicious, add this HTTP header to every outgoing request: X-Bug-Bounty: username
- When testing RCE, SQL, LFR or SSTI, use only the smallest possible PoC to prove the issue (sleep, reading /etc/passwd). If your testing could affect other users or system stability, contact Pachca's security team at security@pachca.com for permission first
Not allowed:
- any activity that could harm the company's applications, infrastructure or customers
- aggressive actions that could cause a denial of service
- social engineering
- physical interference with the company's infrastructure
- publishing or disclosing report details without approval from Pachca's security team
Out-of-scope vulnerabilities and issues:
- vulnerabilities in services unrelated to the Pachca team chat app
- reports from vulnerability scanners and other automated tools
- disclosure of software versions, error messages, stack traces and the like, unless you demonstrate exposure of sensitive data
- disclosure of public user information
- reports based on a product or protocol version without proof that the vulnerability actually exists
- reports about missing security mechanisms or best practices (e.g., no CSRF token or framing/clickjacking protection) without demonstrating a real security impact on users or the system
- reports about published or unpublished SPF and DMARC policies
- CSRF logout
- site scripting, reflected download and similar attacks with questionable impact
- self XSS
- CSP-related reports for domains without CSP or with policies that allow unsafe eval and/or unsafe inline
- Excel and CSV formula injection
- theoretical attacks without a working PoC
- denial of service (DoS) vulnerabilities
- the ability to send a large number of messages
- the ability to send spam or malware files
- disclosure of unused or properly restricted API keys (e.g., an API key for an external mapping service)
- the ability to perform an action that isn't available in the UI, with no identified security risk
- spamming users via OTP, email or other communication channels
Rewards
We pay rewards for reports that meet the participation rules and describe previously unknown security issues.
The reward depends on the severity of the vulnerability:
| Severity | Reward |
|---|---|
| Critical | 80,000 ₽ – 120,000 ₽ |
| High | 45,000 ₽ – 80,000 ₽ |
| Medium | 15,000 ₽ – 45,000 ₽ |
| Low | 3,000 ₽ – 10,000 ₽ |
| Info | No reward |
Besides the severity of the vulnerability itself, the payout depends on the criticality of the affected asset. Here are the multipliers:
| Asset criticality | Multiplier |
|---|---|
| Critical | 1.0 |
| High | 0.75 |
| Medium | 0.5 |
| Low | 0.25 |
Severity assessment
The company's security team makes the final call on a vulnerability's severity and reward, based on its security impact, reputational and business risk, how hard and how likely it is to exploit, and other factors.
Duplicates
Only the first person to report a vulnerability gets a reward. Any later reports of the same vulnerability are marked as duplicates and aren't eligible for a reward.
0-day policy
Publicly disclosed 0-day/1-day vulnerabilities are also treated as duplicates for several days after disclosure if the company's security team already knows about them.
Limitations
Pachca reserves the right to change these Rules or the bug bounty program at any time without prior notice. Any changes to the program or rules will be published. If you keep participating after changes are published, you agree to follow the updated Rules.
Report requirements
Write detailed reports with working steps to reproduce the vulnerability. This speeds up triage and payout if your report qualifies for a reward.
Your report should include:
- a full description of the vulnerability
- its impact on user and/or system security
- steps to reproduce, ideally with screenshots, videos, request and response bodies, exploit code, the date and time of your requests, the IDs of the accounts you tested with and anything else needed to reproduce the issue
- brief remediation recommendations
SLA
We'll do our best to keep you posted:
- Time to first response (from submission): 2 business days
- Time to confirm the vulnerability (from receipt of the report): 7 business days
- Time to calculate the reward (after confirmation): 15 business days
Submitting a report
Found a vulnerability? Email your report to security@pachca.com
Email us