Bug Bounty Program Disclosure Policy


Program Disclosure Policy

Scope

The Bug Bounty Program ("Program") is designed to encourage responsible security research and reporting of security vulnerabilities in Bug Bounty Oman's systems, applications, and platforms.

Eligibility

To be eligible to participate in the Bug Bounty Program, you must:

  • Be at least 18 years old.

· Adhere to the guidelines outlined in this policy.

· Comply with all applicable laws and regulations.

· Report vulnerabilities in accordance with the responsible disclosure guidelines.

· Responsible Disclosure Guidelines

Participants in the Bug Bounty Program must:

· Report any discovered vulnerabilities promptly after identification.

· Provide detailed and clear information about the vulnerability, including steps to reproduce.

· Not disclose the vulnerability to any third parties until it has been resolved by Bug Bounty Oman.

· Avoid exploiting the vulnerability for any reason other than demonstrating the issue to Bug Bounty Oman.

Testing Guidelines and Restrictions

Participants are permitted to:

· Test only the systems, applications, and platforms explicitly mentioned in the program scope.

· Use only testing techniques that do not harm or compromise the availability of Bug Bounty Oman's services.

· Refrain from engaging in any physical attacks, social engineering, or attempts to phish employees.

Participants must not:

· Attempt to access, modify, or destroy data that does not belong to them.

· Engage in any activities that may violate applicable laws or regulations.

· Utilize automated scanning tools that may generate a high volume of false positives.

Rewards and Recognition

Bug Bounty Oman will provide rewards based on the severity and impact of the reported vulnerabilities. The types of vulnerabilities eligible for rewards, as well as the range of rewards, are outlined in the program documentation.

Legal Protections

Bug Bounty Oman commits to not pursue legal action against participants who act in good faith and comply with the guidelines of this program.

Response and Resolution

Bug Bounty Oman will make best efforts to respond to and address reported vulnerabilities in a timely manner. The timeline for resolution may vary depending on the complexity and severity of the reported issue.

Communication Channels

Participants should submit their findings through the platform.

Contact Information

For inquiries related to the Bug Bounty Program, please contact info@bugbounty.om.