Background
Security

Vulnerability Disclosure Policy

Chargezen welcomes security researchers to responsibly disclose vulnerabilities. We're committed to working with the security community to protect our customers.

Effective: January 4, 2026Bug Bounty Active

Report a Vulnerability

Found a security issue? Please report it responsibly. We appreciate your help in keeping Chargezen secure.

Email (Preferred)

security@chargezen.com

PGP key available upon request

Expected Response Time

24 hours

Critical issues: same business day

In Scope

  • chargezen.com and all subdomains
  • admin.chargezen.com (merchant dashboard)
  • api.chargezen.com (REST and GraphQL APIs)
  • Chargezen mobile applications (iOS, Android)
  • Chargezen browser extensions
  • Open source projects under github.com/chargezen

Out of Scope

  • Third-party services and integrations
  • Chargezen employee personal accounts or devices
  • Physical security or social engineering attacks
  • Denial of service (DoS/DDoS) attacks
  • Spam or social engineering
  • Previously reported vulnerabilities
  • Issues requiring physical access to devices

Bug Bounty Rewards

Rewards are determined based on severity, impact, and quality of the report.

Critical

Remote code execution, SQL injection, authentication bypass, data breach

$5,000 - $15,000

Examples:

RCE on production serversSQLi exposing customer dataAuth bypass to admin

High

Significant data exposure, privilege escalation, stored XSS with impact

$1,000 - $5,000

Examples:

Stored XSS affecting other usersIDOR exposing sensitive dataPrivilege escalation

Medium

Limited data exposure, CSRF, reflected XSS, information disclosure

$250 - $1,000

Examples:

Reflected XSSCSRF on state-changing actionsSensitive info in responses

Low

Minor issues, best practice violations, low-impact information disclosure

$50 - $250

Examples:

Missing security headersVerbose error messagesMinor info disclosure

Responsible Disclosure Guidelines

What We Ask of You

  • Provide detailed reports with steps to reproduce
  • Give us reasonable time to fix issues before disclosure (90 days)
  • Do not access, modify, or delete data belonging to others
  • Do not perform attacks that degrade service (DoS)
  • Do not use automated scanning tools without coordination
  • Act in good faith to avoid privacy violations

What We Promise

  • Respond to reports within 24 hours
  • Work with you to understand and validate issues
  • Keep you informed of remediation progress
  • Not pursue legal action for good faith research
  • Publicly recognize researchers (with permission)
  • Pay rewards promptly after validation

What to Include in Your Report

High-quality reports help us fix issues faster and may result in higher rewards.

1

Vulnerability Type

Classification (XSS, SQLi, IDOR, etc.)

2

Affected URL/Endpoint

Specific location of the vulnerability

3

Steps to Reproduce

Clear, numbered steps anyone can follow

4

Proof of Concept

Screenshots, videos, or code demonstrating the issue

5

Impact Assessment

Potential impact if exploited by an attacker

6

Suggested Fix

Optional, but appreciated recommendations

Safe Harbor

When conducting security research according to this policy, we consider this research to be:

  • Authorized: We will not pursue civil or criminal action against researchers acting in good faith.
  • Lawful: We will work with you to understand and resolve issues quickly, and will not file complaints against researchers who comply with this policy.
  • Helpful: We will coordinate disclosure with you and credit you (if desired) when we publish fixes.

Ready to Report?

Help us keep Chargezen secure. Submit your vulnerability report and join our security hall of fame.

Space, at your fingertips

What would you do with 22% more revenue?