Help us secure Admin's infrastructure. Report vulnerabilities responsibly, collaborate with our security team, and earn rewards for valid findings.
A transparent, researcher-friendly process designed to reward responsible disclosure and improve our security posture.
Test only in-scope assets. Follow our guidelines to avoid disrupting production or accessing unauthorized data.
Report via our secure portal or email. Include steps to reproduce, impact analysis, and proof of concept.
Our security team triages within 48 hours. Valid reports are rewarded based on severity and impact.
| Asset | Type |
|---|---|
| WEB app.admin.com | Web Application |
| API api.admin.com/v2/* | REST API |
| AUTH auth.admin.com | Identity Provider |
| MOBILE Admin iOS/Android Apps | Mobile Clients |
| DNS *.admin.com | Infrastructure |
| Category | Details |
|---|---|
| DOSE | Denial of Service / Availability attacks |
| SOC | Social engineering / Phishing |
| THIRD | CDNs, Payment gateways, Third-party scripts |
| PHYS | Physical security / Hardware |
| LOW | Self-XSS, Missing security headers (low risk) |
Payouts are determined by CVSS scoring, real-world impact, and exploit complexity. All rewards are paid via bank transfer or cryptocurrency upon verification.
* Bulk reports of the same class are consolidated. Duplicate reports are acknowledged but not rewarded.
We value responsible disclosure. Follow these guidelines to ensure your research is safe, legal, and rewarded.
We will not pursue legal action against researchers who act in good faith and follow these guidelines. Your cooperation and responsible disclosure are valued and protected.
Send your report to our dedicated security inbox. Include a detailed description, steps to reproduce, impact assessment, and any relevant screenshots or PoC code.
📧 security@admin.comEncryption optional: PGP Key ID: 0x8A4F2C91 | Response time: < 48 hours