Keeping our customers' data safe is a top priority at Appcircle. If you believe you have found a security vulnerability in an Appcircle service, we encourage you to report it to us privately. We review every report and reward valid findings based on their severity.
How to report
- Email your report to security@appcircle.io. Please do not use support tickets or public channels.
- Include a clear title, the affected service or URL, a description of the vulnerability and its impact, and step-by-step reproduction instructions or a proof of concept.
- Reports containing only automated scanner output are not accepted.
Scope
Any exploitable vulnerability that can compromise the integrity of customer data, disclose sensitive information or disrupt the service on the Appcircle cloud platform (my.appcircle.io and its APIs), for example:
- Remote code execution
- SQL or other injection
- Authentication or authorization bypass, including cross-organization data access
- Cross-site scripting (XSS) and cross-site request forgery (CSRF)
- Exposure of sensitive data such as credentials, signing keys or certificates
Out of scope
- Self-hosted Appcircle installations and the marketing website
- Vulnerabilities in third-party services or software we use
- Missing security headers (HSTS, CSP, X-Frame-Options and similar)
- Missing cookie flags, autocomplete settings or mixed content
- Self-XSS, logout CSRF and CSRF on anonymous forms
- Username or email enumeration, verbose error messages and software version disclosure
- Missing rate limiting or brute force without a demonstrated impact
- Social engineering, phishing and physical attacks
- Denial of service attacks
Rules
- Test only against accounts and data you own. Do not access, modify or delete other users' data.
- Do not degrade the service or run high-volume automated scans.
- Give us reasonable time to fix the issue before any public disclosure.
We will not take legal action against researchers who follow these rules and act in good faith.
Rewards
Rewards are paid as gift cards and are based on the severity of the finding:
- Critical: $200
- High: $100
- Medium: $50
- Low: Hall of Fame
- Appcircle determines the final severity and reward.
- Only the first report of a given issue is eligible.
- Rewards are subject to an annual program budget. Once the budget is used, valid reports are acknowledged in the Hall of Fame only.
Hall of Fame
We thank the following researchers for responsibly disclosing security issues to us. Researchers are listed only after the issue is fixed and with their permission.
No entries yet. Be the first!