At FireXCore, cybersecurity is at the heart of our mission. Our Bug Bounty Program invites ethical hackers and security researchers to identify vulnerabilities in our systems, helping us protect our infrastructure and global user base. By participating, you contribute to a safer digital world and earn rewards for your expertise.
Scope of the FireXCore Bug Bounty Program
Our program covers a wide range of assets to ensure comprehensive security testing.
Eligible Targets
- FireXCore Web Applications (e.g., dashboard, customer portal)
- FireXCore Mobile Applications (iOS and Android)
- FireXCore Public API Endpoints
- FireXCore Desktop Applications
Out-of-Scope Targets
- Third-party tools or services not owned by FireXCore
- Social engineering or phishing attacks
- Physical security or hardware exploits
Ethical Hacking Guidelines
To participate in our Safe Harbor policy and qualify for rewards, adhere to these rules:
- Do not access real user accounts or sensitive customer data.
- Do not perform denial-of-service (DoS/DDoS) or spam attacks.
- Test only with accounts you own or in explicitly authorized environments.
- Avoid impacting system availability or integrity during testing.
How to Submit a Vulnerability Report
Submit detailed and actionable vulnerability reports to help us address issues efficiently. Your submission should include:
- A clear explanation of the vulnerability
- Step-by-step reproduction instructions
- Potential impact and proof of concept (PoC), if applicable
- Supporting screenshots or video documentation
Submit your report: FireXCore Vulnerability Submission Form
Bug Bounty Reward Structure
Rewards are based on the CVSS 3.1 scoring system, factoring in severity, exploitability, and real-world impact.
| Severity | Reward Range (USD) | Examples |
|---|---|---|
| Critical | $500 – $1,500 | Remote code execution, full account takeover |
| High | $250 – $500 | SQL injection, privilege escalation, severe IDOR |
| Medium | $100 – $250 | XSS, CSRF, sensitive information exposure |
| Low | $50 – $100 | Clickjacking, security header misconfigurations |
| Informational | Up to $50 | Security best practice recommendations |
Legal Protections and Disclosure Policy
- Safe Harbor: Researchers acting in good faith are protected from legal action.
- Responsible Disclosure: Vulnerabilities must remain confidential until resolved.
- Public Disclosure: Permitted only after 90 days from validation, unless otherwise agreed.
Reward Payment Methods
We offer flexible payment options for bug bounty rewards:
- PayPal
- Bank transfer
- Cryptocurrency (BTC/USDT)
Payments are processed within 30 business days after report validation.
Last Updated: May 13, 2025
Contact Us: For questions, reach out to security@firexcore.com