No technology is perfect and Step believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our mobile apps. Good luck, and happy hunting!
For the initial prioritization/rating of findings, this program will use theBugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.
Last updated 21 Jan 2021 00:51:28 UTC
Technical severity | Reward range
p1 Critical | $4,100 - $4,500
p2 Severe | $1,500 - $1,750
p3 Moderate | $600 - $850
p4 Low | $200 - $250
P5 submissions do not receive any rewards for this program.
This program follows Bugcrowd’s standard disclosure terms.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
This policy crawled by Onyphe on the 2021-02-04 is sorted as bounty.