Security Center

Bug Bounty Program

FindQC welcomes security researchers who help us identify and fix issues. If you report vulnerabilities responsibly, we'll review them carefully and work to address them quickly.

Security Contact:[email protected]

What's in Scope

  • FindQC website & web app (frontend/backend)
  • Authentication flows
  • APIs & integration endpoints
  • Discord bot & related services
  • Search & Link Parsing features

Unsure? Email us a quick note and we'll confirm.

Vulnerability Classification

High PriorityRewards Eligible
  • * Broken Access Control / IDOR
  • * Account Takeover / Auth Bypass
  • * Remote Code Execution (RCE)
  • * SQL Injection / SSRF
  • * Sensitive Data Exposure
  • * Severe Business Logic Flaws
Medium Priority
  • * Stored/Reflected XSS with impact
  • * CSRF leading to state change
  • * Rate-limit bypass for abuse
Low Priority
  • * Cosmetic issues / Best practice suggestions
  • * Theoretical risks without exploit

Rules & Out of Scope

Responsible Disclosure

  • + Don't access/modify real user data
  • + Avoid automated scanning impacting uptime
  • + Only exploit enough to prove the bug
  • + Wait for fix before public disclosure

Strictly Out of Scope

  • x Social Engineering (Phishing)
  • x DDoS or Load Testing
  • x Physical attacks / Device theft
  • x 3rd party systems out of our control

Submission Process

Email Report

Send finding to [email protected] with steps & PoC.

Acknowledgment

We confirm receipt (usually within 48h).

Verification

We verify the bug and assess severity.

Fix & Validation

We patch the issue and verify the fix.

Outcome

We inform you of the result, reward, or credit.

Rewards

We value your time. High-quality reports with real impact are eligible for:

  • Cash Bounties
  • Public Hall of Fame
  • Discord Badge/Role

Quick Report Template

To: [email protected] Subject: [Bug Bounty] <Type> - <Short description> Body: Vulnerability type: Affected page/endpoint: Impact: Reproduction steps: PoC (redacted): Exploit conditions: Suggested fix: