Bug Bounty Program

Security is foundational to how we build Scape. We welcome security researchers to responsibly report vulnerabilities in our products and services, and we reward valid findings.

Scope

  • scape.app and its subdomains
  • The Scape desktop app
  • Our public APIs

Assets not explicitly listed above require prior authorization. Ask us first through the report form below, with Other asset selected, before testing anything else.

Rules

  • Do not access, modify, or expose user data.
  • Do not disrupt services or perform destructive testing.
  • No phishing, social engineering, or attacks against employees or customers.
  • Report vulnerabilities privately with a clear proof of concept and reproduction steps.
  • Give us reasonable time to remediate before any public disclosure.
  • If you create accounts or sign up for the waitlist while testing, use plus addressing: yourname+bugbounty@yourdomain.com. This keeps test signups out of our metrics.
  • Submit reports in the required format described under Report format below.

Rewards

We classify each report as Critical, High, Medium, or Low severity based on its impact and exploitability, and rewards scale with severity. Depending on severity, rewards typically range from hundreds to thousands of dollars. Reward amounts are determined at our discretion, taking report quality into account. Duplicate or previously known issues may not qualify for rewards. Reports that skip the required report format, and testing done from accounts without +bugbounty addressing, are not eligible for rewards. We reserve discretion to make exceptions for outstanding findings.

Safe harbor

Researchers who follow this policy and act in good faith will not face legal action from us for their authorized security testing.

Report format

Use the form below to compose your report. It opens your email app with the required subject line and a structured body. Reports must use this subject format:

[bug-bounty][severity] asset - title, for example [bug-bounty][high] website - Stored XSS in profile name. Severity is one of critical, high, medium, or low. Asset is one of website, desktop-app, or other.

0/80
0/400
0/750
0/300

Send report opens your email app with the required subject line: [bug-bounty][medium] desktop-app -

How to report

Compose and send your report with the form above. If you need more room, link to a video or gist, or send extra material in a follow-up reply. We take every report seriously. We aim to acknowledge critical reports within 2 business days and all other reports within a week.

Scape AB · Luntmakargatan 26, 111 37 Stockholm, Sweden