BUG BOUNTY · 4 TIERS
Break it. Get paid.
Critical
$25,000
Pre-auth RCE on tunnel servers. Cleartext recovery of in-transit user traffic. Vault key disclosure across accounts.
High
$8,000
Auth bypass on account portal. Cross-account data read in Drive. Bypass of lawful-intercept dual-key admin authorisation.
Medium
$2,000
Stored XSS in account portal. Prediction of session tokens. CSRF on billing endpoints.
Low
$400
Reflected XSS on marketing surfaces. Disclosure of internal hostnames. SSRF that does not pivot.
◆
Scope.
✓ In scope
*.bayria.com
in scope
iOS / macOS / Windows / Linux client binaries
in scope
github.com/bayria-org/* releases
in scope
Tunnel POPs · pop-*.bayria.systems
in scope
✕ Out of scope
status.bayria.com
rate-limited public probes; report only logic flaws
Third-party SaaS we use (Stripe, Postmark)
report to them
Social engineering against employees
not eligible
★
Hall of fame.
2026 H1
@anvilbones
Tunnel handshake replay across regions
$25,000
@kira_q
Drive · cross-account share link forgery
$8,000
@rhys.olive
Account portal · OAuth callback open redirect
$8,000
@tn3-anon
Stored XSS in vault note rendering
$2,000
@vitr-1
CSRF on plan-change endpoint
$2,000
@still-meadow
Reflected XSS on /help search
$400