Last Updated: February 11, 2026
Bug Bounty Program
At StockDrifts, the security of our platform and protection of our users' data is a top priority. We encourage responsible disclosure of security vulnerabilities through our Bug Bounty Program. Security researchers who identify and report valid vulnerabilities in accordance with this policy may be eligible for monetary rewards.
Policy
To participate in our Bug Bounty Program, you must follow this policy at all times, which includes:
- Acting in good faith and avoiding any policy violations
- Using the minimum effort necessary to demonstrate a vulnerability exists
- Avoiding threats, ransom demands, or extortion
- Reporting vulnerabilities promptly with clear instructions and proof-of-concept exploits
- Complying with all applicable laws and regulations
- Understanding that violations of this policy will result in ineligibility for the program
For clarification on any aspect of this policy, contact app@stockdrifts.io.
Coordinated Disclosure
StockDrifts supports coordinated vulnerability disclosure and agrees not to initiate legal action for security research that complies with this policy, including good faith accidental violations.
Data Protection
Researchers must adhere to the following data protection rules:
- Maintain strict confidentiality of all vulnerabilities until StockDrifts grants permission for disclosure
- Avoid deliberately violating user privacy — create test accounts when possible
- Never store or transmit other users' personally identifiable information
- Immediately report and destroy any captured PII
- Delete all collected data after submission confirmation
- Do not disclose findings to third parties without written consent from StockDrifts
Submission Requirements
- Never include threats or extortion attempts in submissions
- Submit reports to app@stockdrifts.io only (official contact)
- Do not use external portals or unofficial channels
- Provide detailed step-by-step reproduction instructions and proof-of-concept
- Include your preferred payment method for reward (PayPal or bank transfer)
- Minimum payout: $250 USD
Legal Framework
StockDrifts considers compliant research activities to constitute "authorized" conduct under the Computer Fraud and Abuse Act and applicable anti-hacking laws. Researchers remain responsible for understanding and complying with all applicable local and international laws.
Submission Process Timeline
Report Submission
Submit your report to the bug bounty mailbox
Acknowledgment
Security acknowledgment within 1 business day
Triage
Triage by StockDrifts security team within 10 business days
Determination
Response with determination and severity level
Reward
Reward issuance for verified vulnerabilities within 14 business days
Payout Scale
| Severity | Reward Range |
|---|---|
| Low | $250 – $500 |
| Medium | $1,000 – $2,500 |
| High | $5,000 – $15,000 |
In Scope Targets
| Target | Description |
|---|---|
| stockdrifts.io | Main Website |
| app.stockdrifts.io | Dashboard Application |
| api.stockdrifts.io | REST API |
Vulnerability Severity Definitions
High Severity
Unauthorized access to sensitive data or production systems, including:
- Arbitrary code execution
- Database query manipulation (SQL injection)
- Authentication bypass
- XSS bypassing Content Security Policy
- Publicly exposed sensitive user data
Medium Severity
Limited unauthorized data access, including:
- Non-sensitive production information disclosure
- XSS without CSP bypass
- Low-risk CSRF
Low Severity
Extremely limited data access, such as:
- Debug error pages without exploitability proof or privilege escalation
Ineligibility Criteria
StockDrifts does not reward reports involving:
- Third-party hosted vulnerabilities unless they directly affect the main website
- Physical attacks, social engineering, spam, or DDoS attacks
- Outdated browser vulnerabilities
- Third-party application vulnerabilities using StockDrifts API
- Publicly disclosed third-party library issues within 30 days of disclosure
- Previously reported or publicly known vulnerabilities
- Non-reproducible issues
- Issues requiring improbable user interaction
- Mobile jailbreak or root requirements
- Missing security headers without proof of exploitability
- TLS cipher suite listings
- Best practice suggestions without security impact
- Software version disclosure
- Reports lacking detailed step-by-step instructions and proof-of-concept
- Automated tool or AI-generated outputs
- Issues without demonstrable security impact
Non-security issues should be reported to app@stockdrifts.io.
Contact
For all bug bounty submissions and inquiries: app@stockdrifts.io