Skip to main content
Engineering Service

Bug Bounty Program Terms

At FireXCore, cybersecurity is at the heart of our mission. Our Bug Bounty Program invites ethical hackers and security researchers to identify vulnerabilities in our systems, helping us protect our infrastructure and global user base. By participating, you contribute to a safer digital world and earn rewards for your expertise. Scope of the FireXCore Bug […]

CapabilityFireXCore Engineering DeliveryScoped engineering
firexcore / service active
Bug Bounty Program Terms
Engineering Service FireXCore Engineering
Service detail FireXCore Engineering

At FireXCore, cybersecurity is at the heart of our mission. Our Bug Bounty Program invites ethical hackers and security researchers to identify vulnerabilities in our systems, helping us protect our infrastructure and global user base. By participating, you contribute to a safer digital world and earn rewards for your expertise.

Scope of the FireXCore Bug Bounty Program

Our program covers a wide range of assets to ensure comprehensive security testing.

Eligible Targets

  • FireXCore Web Applications (e.g., dashboard, customer portal)
  • FireXCore Mobile Applications (iOS and Android)
  • FireXCore Public API Endpoints
  • FireXCore Desktop Applications

Out-of-Scope Targets

  • Third-party tools or services not owned by FireXCore
  • Social engineering or phishing attacks
  • Physical security or hardware exploits

Ethical Hacking Guidelines

To participate in our Safe Harbor policy and qualify for rewards, adhere to these rules:

  • Do not access real user accounts or sensitive customer data.
  • Do not perform denial-of-service (DoS/DDoS) or spam attacks.
  • Test only with accounts you own or in explicitly authorized environments.
  • Avoid impacting system availability or integrity during testing.

How to Submit a Vulnerability Report

Submit detailed and actionable vulnerability reports to help us address issues efficiently. Your submission should include:

  • A clear explanation of the vulnerability
  • Step-by-step reproduction instructions
  • Potential impact and proof of concept (PoC), if applicable
  • Supporting screenshots or video documentation

Submit your report: FireXCore Vulnerability Submission Form

Bug Bounty Reward Structure

Rewards are based on the CVSS 3.1 scoring system, factoring in severity, exploitability, and real-world impact.

Severity Reward Range (USD) Examples
Critical $500 – $1,500 Remote code execution, full account takeover
High $250 – $500 SQL injection, privilege escalation, severe IDOR
Medium $100 – $250 XSS, CSRF, sensitive information exposure
Low $50 – $100 Clickjacking, security header misconfigurations
Informational Up to $50 Security best practice recommendations

Legal Protections and Disclosure Policy

  • Safe Harbor: Researchers acting in good faith are protected from legal action.
  • Responsible Disclosure: Vulnerabilities must remain confidential until resolved.
  • Public Disclosure: Permitted only after 90 days from validation, unless otherwise agreed.

Reward Payment Methods

We offer flexible payment options for bug bounty rewards:

  • PayPal
  • Bank transfer
  • Cryptocurrency (BTC/USDT)

Payments are processed within 30 business days after report validation.


Last Updated: May 13, 2025

Contact Us: For questions, reach out to security@firexcore.com

FAQ

Frequently Asked Questions

01 What types of vulnerabilities qualify for rewards in the FireXCore Bug Bounty Program?

Vulnerabilities that impact the security of FireXCore’s eligible targets, such as remote code execution, SQL injection, XSS, or privilege escalation, qualify for rewards. The reward amount depends on the severity, as outlined in our reward structure.

02 Can I test FireXCore systems without prior authorization?

Testing is only permitted on accounts you own or in environments explicitly authorized by FireXCore. Unauthorized testing, including accessing real user data or performing DoS attacks, violates our guidelines and is not eligible for rewards.

03 How long does it take to receive a bug bounty reward?

Once a vulnerability report is validated, rewards are processed within 30 business days. Payments are made via PayPal, bank transfer, or cryptocurrency (BTC/USDT).

04 What is FireXCore’s Safe Harbor policy?

Our Safe Harbor policy protects ethical hackers who follow our guidelines from legal action. This ensures you can report vulnerabilities in good faith without fear of repercussions.

05 How does FireXCore handle responsible disclosure?

We require vulnerabilities to remain confidential until resolved. Public disclosure is allowed only after 90 days from validation, unless otherwise agreed with FireXCore’s security team.

Engineering conversation

Bring the system, constraints and current state.