Scope
Our bug bounty program covers the following assets:
- API: api.kernelflow.one (v1 and v2)
- Dashboard: dashboard.kernelflow.one
- Authentication: auth.kernelflow.one
- CLI: kf-cli (versions 4.0.0 and above)
Rewards
We reward based on severity and impact of the vulnerability:
- Critical (RCE, SQLi, Auth Bypass): $2,000 – $5,000
- High (XSS, IDOR, Privilege Escalation): $500 – $2,000
- Medium (CSRF, Information Disclosure): $200 – $500
- Low (Missing Security Headers): $50 – $200
Safe Harbor
We will not take legal action against researchers who:
- Follow our responsible disclosure policy.
- Do not cause harm to our systems or users.
- Do not access or exfiltrate customer data.
- Give us a reasonable time to fix the issue before disclosing publicly.
🔍 How to Report: Send your report to security@kernelflow.one with a detailed description, steps to reproduce, and proof-of-concept.
Out of Scope
- Social engineering, phishing, or physical attacks.
- Denial-of-service (DoS) attacks.
- Issues related to third-party services (, Stripe, etc.).
- Vulnerabilities that have already been reported.