Last Updated: April 2026
If you have discovered a security vulnerability on phodan.com, we encourage you to report it immediately. Phodan LLC takes the security of our platform, customer accounts, and payment information seriously. We review all legitimate reports and work quickly to resolve confirmed issues. Please read this page carefully before submitting a report.

Fundamentals

If you follow the principles below when reporting a security issue to Phodan LLC, we will not initiate legal action or enforcement investigations against you in response to your report.

We ask that you:

  1. Give us reasonable time to investigate and resolve the issue before public disclosure.
  2. Do not access, modify, or expose private customer accounts without explicit permission.
  3. Make a good-faith effort to avoid privacy violations, service interruptions, or data destruction.
  4. Do not exploit the vulnerability for personal gain or to access sensitive customer information.
  5. Comply with all applicable local, state, federal, and international laws.

Bug Bounty Program

Phodan LLC values responsible security researchers who help us protect our customers and our ecommerce platform. Bounties are awarded at our sole discretion based on severity, exploitability, impact, and report quality.

To potentially qualify for a reward, you must:

  1. Follow all fundamentals listed above.
  2. Submit a valid vulnerability that presents a genuine security risk.
  3. Send your report directly to Contact@phodan.com.
  4. Disclose any accidental access to sensitive information during your testing.
  5. Provide enough technical detail for our team to reproduce the issue.
  6. Understand that investigation time depends on issue severity and complexity.
  7. Agree that Phodan LLC may publish resolved reports at our discretion.

Rewards

Rewards are based on the severity and business impact of the reported issue. The first valid report of a unique vulnerability receives the bounty. Duplicate reports may not be eligible.

🔴 Critical Severity — $500

  • Remote Code Execution
  • Full account takeover
  • SQL Injection exposing sensitive customer data
  • Authentication bypass with admin access
  • Payment system compromise

🟠 High Severity — $250

  • Stored XSS affecting customers
  • Disclosure of sensitive internal data
  • Privilege escalation
  • Insecure authentication/session handling
  • Local file inclusion

🟡 Medium Severity — $100

  • Business logic flaws
  • CSRF on sensitive actions
  • IDOR vulnerabilities
  • Security misconfigurations
  • Unvalidated redirects

🟢 Low Severity — Recognition Only

  • Open redirects
  • Reflected XSS
  • Low-risk information disclosure
  • Missing security headers
  • Minor misconfigurations

Non-Reportable Issues

The following are generally considered out of scope and are not eligible for bounty rewards:

  • Denial of Service (DoS / DDoS) attacks or testing
  • Spam, phishing, or social engineering attacks
  • Physical security issues
  • Third-party plugin issues outside our direct control
  • Automated scanner reports without manual verification
  • Previously known or already reported vulnerabilities

How to Submit a Report

Please send your report to Contact@phodan.com using the subject line: Security Vulnerability Report – phodan.com

Your report should include:

  • A clear description of the vulnerability
  • Step-by-step instructions to reproduce the issue
  • The potential impact on customers or systems
  • Screenshots, videos, or proof-of-concept if available
  • Your contact information for follow-up communication

We aim to acknowledge valid reports within 3 business days and will keep you informed throughout the investigation process.

Contact Us

Mon – Fri: 9:00 AM – 6:00 PM MST
Saturday: Closed
Sunday: Closed
```