Bug Bounty
Last updated 12 June 2026
Scope
This program covers shellkode.com and the production infrastructure we operate directly. Client-owned systems we have delivered are out of scope-report those to the client that owns them.
What to report
We want to hear about vulnerabilities that affect confidentiality, integrity, or availability-injection flaws, auth bypass, exposed credentials, and similar. Low-severity findings like missing security headers are welcome but triaged separately.
Rules of engagement
Test only against your own accounts and data. Do not run automated scanners against production without asking first, do not attempt denial-of-service, and stop and report immediately if you access another user's data.
How to report
Email security@shellkode.com with steps to reproduce, impact, and any proof-of-concept. We acknowledge reports within two business days and aim to triage within ten.
Recognition
Valid reports are credited in our security acknowledgements with your permission. We do not currently offer paid bounties, but we recognise every genuine finding.
Contact us
security@shellkode.com is monitored for this program specifically-use it rather than general enquiry channels.











