Fundamentals
If you follow the principles below when reporting a security issue to Phodan LLC, we will not initiate legal action or enforcement investigations against you in response to your report.
We ask that you:
- Give us reasonable time to investigate and resolve the issue before public disclosure.
- Do not access, modify, or expose private customer accounts without explicit permission.
- Make a good-faith effort to avoid privacy violations, service interruptions, or data destruction.
- Do not exploit the vulnerability for personal gain or to access sensitive customer information.
- Comply with all applicable local, state, federal, and international laws.
Bug Bounty Program
Phodan LLC values responsible security researchers who help us protect our customers and our ecommerce platform. Bounties are awarded at our sole discretion based on severity, exploitability, impact, and report quality.
To potentially qualify for a reward, you must:
- Follow all fundamentals listed above.
- Submit a valid vulnerability that presents a genuine security risk.
- Send your report directly to Contact@phodan.com.
- Disclose any accidental access to sensitive information during your testing.
- Provide enough technical detail for our team to reproduce the issue.
- Understand that investigation time depends on issue severity and complexity.
- Agree that Phodan LLC may publish resolved reports at our discretion.
Rewards
Rewards are based on the severity and business impact of the reported issue. The first valid report of a unique vulnerability receives the bounty. Duplicate reports may not be eligible.
🔴 Critical Severity — $500
- Remote Code Execution
- Full account takeover
- SQL Injection exposing sensitive customer data
- Authentication bypass with admin access
- Payment system compromise
🟠 High Severity — $250
- Stored XSS affecting customers
- Disclosure of sensitive internal data
- Privilege escalation
- Insecure authentication/session handling
- Local file inclusion
🟡 Medium Severity — $100
- Business logic flaws
- CSRF on sensitive actions
- IDOR vulnerabilities
- Security misconfigurations
- Unvalidated redirects
🟢 Low Severity — Recognition Only
- Open redirects
- Reflected XSS
- Low-risk information disclosure
- Missing security headers
- Minor misconfigurations
Non-Reportable Issues
The following are generally considered out of scope and are not eligible for bounty rewards:
- Denial of Service (DoS / DDoS) attacks or testing
- Spam, phishing, or social engineering attacks
- Physical security issues
- Third-party plugin issues outside our direct control
- Automated scanner reports without manual verification
- Previously known or already reported vulnerabilities
How to Submit a Report
Please send your report to Contact@phodan.com using the subject line: Security Vulnerability Report – phodan.com
Your report should include:
- A clear description of the vulnerability
- Step-by-step instructions to reproduce the issue
- The potential impact on customers or systems
- Screenshots, videos, or proof-of-concept if available
- Your contact information for follow-up communication
We aim to acknowledge valid reports within 3 business days and will keep you informed throughout the investigation process.
Contact Us
Saturday: Closed
Sunday: Closed