Bug Bounty Program

Bug Bounty Program

Help us keep Keevala secure. Report vulnerabilities responsibly and earn rewards.

Program Scope

Focus on security vulnerabilities affecting Keevala's infrastructure and user data

Rewards

Competitive bounties based on vulnerability severity and impact assessment

Response Time

Acknowledgment within 24 hours, resolution prioritized by severity

Eligible Vulnerabilities

In Scope

  • Authentication bypass and privilege escalation
  • SQL injection and cross-site scripting (XSS)
  • Cross-site request forgery (CSRF) attacks
  • Insecure direct object references (IDOR)
  • Sensitive data exposure and encryption issues

Out of Scope

  • Spam, social engineering, or physical attacks
  • Missing security best practices without direct impact
  • Self-XSS or low-impact UI/UX issues
  • Denial of service without authentication bypass
  • Issues already reported or publicly known

Reward Structure

Low

$50 - $200

Minor issues with limited impact

Medium

$200 - $500

Moderate impact on security

High

$500 - $2000

Significant security impact

Critical

$2000+

Severe vulnerabilities with major impact

Reporting Process

1

Submit Report

Send detailed vulnerability report to security@keevala.comwith proof-of-concept, steps to reproduce, and potential impact.

2

Verification

Our security team reviews and validates the vulnerability. You'll receive acknowledgment within 24 hours.

3

Resolution

We prioritize fixes based on severity. Critical issues receive immediate attention and patches within 72 hours.

4

Reward

Upon successful resolution and disclosure, eligible reports receive agreed-upon rewards via secure payment methods.

Program Guidelines

Help us maintain a secure environment for our users and community

Prohibited Actions

  • • Accessing, modifying, or deleting other users' data
  • • Performing denial of service attacks
  • • Social engineering or phishing attempts
  • • Disclosing vulnerabilities publicly before resolution
  • • Testing on production systems without explicit permission

Best Practices

  • • Provide clear, reproducible proof-of-concepts
  • • Respect user privacy and data confidentiality
  • • Follow responsible disclosure timelines
  • • Focus on security impact and potential exploitation
  • • Include recommendations for remediation

Questions about our bug bounty program? Contact our security team.

Coming Soon