Skip to content

Bug Bounty

Last updated 12 June 2026

Scope

This program covers shellkode.com and the production infrastructure we operate directly. Client-owned systems we have delivered are out of scope-report those to the client that owns them.

What to report

We want to hear about vulnerabilities that affect confidentiality, integrity, or availability-injection flaws, auth bypass, exposed credentials, and similar. Low-severity findings like missing security headers are welcome but triaged separately.

Rules of engagement

Test only against your own accounts and data. Do not run automated scanners against production without asking first, do not attempt denial-of-service, and stop and report immediately if you access another user's data.

How to report

Email security@shellkode.com with steps to reproduce, impact, and any proof-of-concept. We acknowledge reports within two business days and aim to triage within ten.

Recognition

Valid reports are credited in our security acknowledgements with your permission. We do not currently offer paid bounties, but we recognise every genuine finding.

Contact us

security@shellkode.com is monitored for this program specifically-use it rather than general enquiry channels.