StockDrifts LogoStockDrifts
HomeLegal

Last Updated: February 11, 2026

Bug Bounty Program

At StockDrifts, the security of our platform and protection of our users' data is a top priority. We encourage responsible disclosure of security vulnerabilities through our Bug Bounty Program. Security researchers who identify and report valid vulnerabilities in accordance with this policy may be eligible for monetary rewards.

Policy

To participate in our Bug Bounty Program, you must follow this policy at all times, which includes:

  • Acting in good faith and avoiding any policy violations
  • Using the minimum effort necessary to demonstrate a vulnerability exists
  • Avoiding threats, ransom demands, or extortion
  • Reporting vulnerabilities promptly with clear instructions and proof-of-concept exploits
  • Complying with all applicable laws and regulations
  • Understanding that violations of this policy will result in ineligibility for the program

For clarification on any aspect of this policy, contact app@stockdrifts.io.

Coordinated Disclosure

StockDrifts supports coordinated vulnerability disclosure and agrees not to initiate legal action for security research that complies with this policy, including good faith accidental violations.

Data Protection

Researchers must adhere to the following data protection rules:

  • Maintain strict confidentiality of all vulnerabilities until StockDrifts grants permission for disclosure
  • Avoid deliberately violating user privacy — create test accounts when possible
  • Never store or transmit other users' personally identifiable information
  • Immediately report and destroy any captured PII
  • Delete all collected data after submission confirmation
  • Do not disclose findings to third parties without written consent from StockDrifts

Submission Requirements

  • Never include threats or extortion attempts in submissions
  • Submit reports to app@stockdrifts.io only (official contact)
  • Do not use external portals or unofficial channels
  • Provide detailed step-by-step reproduction instructions and proof-of-concept
  • Include your preferred payment method for reward (PayPal or bank transfer)
  • Minimum payout: $250 USD

Legal Framework

StockDrifts considers compliant research activities to constitute "authorized" conduct under the Computer Fraud and Abuse Act and applicable anti-hacking laws. Researchers remain responsible for understanding and complying with all applicable local and international laws.

Submission Process Timeline

1

Report Submission

Submit your report to the bug bounty mailbox

2

Acknowledgment

Security acknowledgment within 1 business day

3

Triage

Triage by StockDrifts security team within 10 business days

4

Determination

Response with determination and severity level

5

Reward

Reward issuance for verified vulnerabilities within 14 business days

Payout Scale

SeverityReward Range
Low$250 – $500
Medium$1,000 – $2,500
High$5,000 – $15,000

In Scope Targets

TargetDescription
stockdrifts.ioMain Website
app.stockdrifts.ioDashboard Application
api.stockdrifts.ioREST API

Vulnerability Severity Definitions

High Severity

Unauthorized access to sensitive data or production systems, including:

  • Arbitrary code execution
  • Database query manipulation (SQL injection)
  • Authentication bypass
  • XSS bypassing Content Security Policy
  • Publicly exposed sensitive user data

Medium Severity

Limited unauthorized data access, including:

  • Non-sensitive production information disclosure
  • XSS without CSP bypass
  • Low-risk CSRF

Low Severity

Extremely limited data access, such as:

  • Debug error pages without exploitability proof or privilege escalation

Ineligibility Criteria

StockDrifts does not reward reports involving:

  • Third-party hosted vulnerabilities unless they directly affect the main website
  • Physical attacks, social engineering, spam, or DDoS attacks
  • Outdated browser vulnerabilities
  • Third-party application vulnerabilities using StockDrifts API
  • Publicly disclosed third-party library issues within 30 days of disclosure
  • Previously reported or publicly known vulnerabilities
  • Non-reproducible issues
  • Issues requiring improbable user interaction
  • Mobile jailbreak or root requirements
  • Missing security headers without proof of exploitability
  • TLS cipher suite listings
  • Best practice suggestions without security impact
  • Software version disclosure
  • Reports lacking detailed step-by-step instructions and proof-of-concept
  • Automated tool or AI-generated outputs
  • Issues without demonstrable security impact

Non-security issues should be reported to app@stockdrifts.io.

Contact

For all bug bounty submissions and inquiries: app@stockdrifts.io