Detective at a laptop tracking down a bug

BisectHosting
Bug Bounty Program

Protecting the players and communities who rely on our infrastructure is central to delivering exceptional server hosting services. With that in mind, the BisectHosting bug bounty program invites security researchers to responsibly report vulnerabilities, and we reward eligible findings that help keep our platform secure.

About the program

BisectHosting's bug bounty program was built on a simple principle: the people best equipped to find weaknesses in our platform are often outside of it. With this program, we invite independent security researchers to test our public-facing systems as defined within the Program Scope and report potential vulnerabilities through a clear, responsible disclosure process.

Our security team reviews each valid report to verify the vulnerability, understand its potential impact, and determine whether it qualifies for a bounty. Researchers receive clear communication throughout the process, and eligible reports are rewarded based on our Rewards & Payout Structure.

Program Scope

Our bug bounty program covers the BisectHosting systems and services listed below. Before beginning any security testing, please review the program scope carefully.

Out of Scope

Unless specifically identified as in scope above, third-party services, customer-owned servers, and systems or infrastructure not owned or operated by BisectHosting are outside the scope of the program and are not eligible for a bounty.

If you're unsure whether a system is included in the program, please contact our security team before testing.

Rules of Engagement

We encourage security researchers to explore our in-scope systems and help us identify vulnerabilities, but all testing must be performed responsibly. To protect our customers, employees, and infrastructure, all researchers participating in the BisectHosting bug bounty program must follow these rules:

  • Only test systems and services explicitly defined as in scope.
  • Do not intentionally disrupt, degrade, or damage BisectHosting services or infrastructure.
  • Do not perform denial-of-service (DoS/DDoS) or other high-volume testing that could affect service availability.
  • Do not use social engineering, phishing, or other attacks targeting BisectHosting employees, customers, or partners.
  • Do not intentionally access, modify, delete, download, or retain data belonging to other users.
  • Use your own accounts and data whenever possible when demonstrating a vulnerability.
  • If you unexpectedly encounter sensitive or customer data, stop testing and report the vulnerability to us immediately.
  • Do not publicly disclose vulnerabilities before receiving authorization from BisectHosting.
  • Provide enough information for our security team to safely reproduce and validate your findings.

Reports resulting from testing that violates these Rules of Engagement may not be eligible for a bounty.

Rewards & Payout Structure

We pay for eligible findings that meet the submission criteria and Rules of Engagement outlined on this page.

Our security team triages every eligible report, assigning a severity rating with help from the CVSS v3 calculator. Ultimately, severity is what determines the payout. However, reports of higher clarity and completeness help in identifying the correct severity.

SeverityPayout
CriticalUrgent$2000
High$1000
ImportantNormal$200
Low$100

Report a Bug

Found a vulnerability? Submit the details below and our security team will review your report. Please include clear reproduction steps, supporting evidence, and details about the vulnerability's potential impact so we can reproduce and validate the issue as quickly as possible.

Fields marked with an asterisk (*) are required

Attachments

Screenshots or text files, up to 5 files, 5MB each.

Frequently asked questions

Join the Bisect team!

See available positions
. . .TR(USD)
BisectHosting Logo