Bug Bounty & Responsible Disclosure
Security researchers keep Vincony safe. Report a vulnerability in good faith and we'll work with you to fix it fast — and credit and reward you for it.
Safe harbor
We will not pursue or support legal action against anyone who discovers and reports a security vulnerability in good faith and in accordance with this policy. We consider such research to be authorized, will work with you to understand and resolve the issue quickly, and will not report you to law enforcement for good-faith research.
To stay protected, please: stay within the scope below, only ever use your own or test accounts, avoid accessing or modifying data that isn't yours, avoid privacy violations and service disruption, and give us reasonable time to remediate before any public disclosure. If in doubt, email security@vincony.com before testing.
In scope
- vincony.com and the marketing site
- app.vincony.com (the product), admin.vincony.com, affiliate.vincony.com
- The Vincony API and developer endpoints (see /docs/api)
- Authentication, billing/credits, team & workspace features
Out of scope
- Third-party services we use (Stripe, Cloudflare, Resend, model providers) — report those to the vendor
- Social engineering, phishing, or physical attacks against staff or users
- Denial of service (DoS/DDoS), volumetric, or resource-exhaustion attacks
- Automated scanner output without a working, demonstrated proof of concept
- Spam, content-policy abuse, or anything that degrades service for others
Rewards
Valid, in-scope reports are rewarded in Vincony account credits plus a Hall of Fame credit. Amounts below are guidelines — the final reward is at our discretion based on impact, exploitability, and report quality. Exceptional critical findings may also earn a cash reward.
| Severity | Reward |
|---|---|
| Critical | up to 100,000 credits |
| High | up to 30,000 credits |
| Medium | up to 7,500 credits |
| Low | 1,000 credits / swag |
Report a vulnerability
A good report includes: the affected component/URL, a severity estimate, clear step-by-step reproduction, the security impact, a proof of concept, and (ideally) a suggested fix. Prefer email? Write to security@vincony.com — PGP available on request.
Rules of engagement
- Only test against your own or dedicated test accounts
- Never access, modify, or delete data that isn't yours
- No DoS/DDoS, spam, social engineering, or physical attacks
- Stop and report immediately if you access sensitive data
- One distinct issue per report; include a clear PoC
- Coordinated disclosure — give us time to fix (up to 90 days) before going public
What to expect
- First response within 3 business days
- Triage and severity assessment within 7 business days
- Regular status updates until the issue is resolved
- Reward + Hall of Fame credit after the fix is verified
- We're happy to coordinate a public write-up once it's patched
Hall of Fame
No reports yet — be the first. Every researcher who reports a valid, in-scope issue is credited here (unless you'd rather stay anonymous).
Disclosure policy
We practice coordinated disclosure. Please keep vulnerability details private until we've confirmed a fix. Attempting to extort Vincony, or threatening to publicly disclose or sell a vulnerability to pressure a reward, voids safe-harbor protection and disqualifies the report. This program is offered at the discretion of VINCONY AI LTD and may change at any time; it doesn't grant permission to act in ways that violate the law or our Terms of Service.