> ## Documentation Index
> Fetch the complete documentation index at: https://docs.appsignal.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security vulnerability disclosure and bug bounties

AppSignal takes security seriously. We welcome reports from security researchers who identify potential vulnerabilities in our platform. We may award bounties for your report. In this program, we set out the guidelines to qualify for a possible bounty.

The program is offered at full discretion of AppSignal.

## How to report

Report vulnerabilities via [security@appsignal.com](mailto:security@appsignal.com). Include a clear description of the issue, steps to reproduce, and any supporting evidence such as screenshots or a video proof of concept. We aim to resolve reported vulnerabilities in a timely manner, though resolution timelines vary depending on severity and our current workload.

## Scope

The following AppSignal-owned domains are in scope:

* [appsignal.com](https://appsignal.com)

**Note:** Please notice that email configuration and marketing websites are not included in this scope.

## What we consider for a bounty

We pay bounties on a case-by-case basis. The bounty depends on the severity of the issue and whether it is already known to us.

To qualify, a finding must be a concrete issue that leads to data being accessed that one should not have access to. The use of generative AI tools for finding bugs may be accepted, but the bug hunter **must** make sure to manually verify that the bug is real. Reports that meet this bar might include issues such as the following, **all of which are subject to our review and confirmation**:

* **A flaw that gives an attacker access to data or resources they should not have.** For example: a bug in an invitation or account verification flow that allows someone to gain access to an organization they were never legitimately invited to.
* **A logic flaw with a clear, demonstrable exploit path.** We need to be able to reproduce the issue and confirm the unauthorized access ourselves. Describing a theoretical chain of steps is not enough, we need to see it work.

## What we do not pay bounties for

* **Findings from automated security scanning tools.** We are aware of all issues that show up in these tools and will not pay a bounty for them.
* **Rate limiting configurations.** We set rate limits as we see fit and do not pay bounties for reports about them.
* **Issues we have investigated and determined are not a vulnerability.** This includes behaviors that are the result of a deliberate product decision. For example, we offer full session management and a 'log out everywhere' option, and we consider this sufficient for managing active sessions across devices.

## Payments

If you are granted a bounty, we pay bounties via Wise (preferred) or PayPal. We confirm the payment method after reviewing and accepting a report.

## Our process

We will review your report and get back to you. We may ask for more information or a proof of concept. If we cannot find an exploitable angle, we will let you know. If you can explain how to exploit it, we are open to looking at it again.

## Guidelines for qualification

While we welcome your reports on potential vulnerabilities in our platform, the security, availability and stability of our platform is of utmost importance to us. Therefore, we will only consider reports that meet the guidelines of this program.

To be considered for a possible bounty, your report and security research must meet the following guidelines:

* The vulnerability must be a part of our software that was developed by us. Our program does not cover vulnerabilities in third party software that may be part of our software.
* The vulnerability is not yet known to us and has not been discovered by us or reported by other security researchers prior to your report.
* You act in good faith and do not intend to cause harm to us or our users.
* You must prevent any access, storage, modification or deletion of our data or data of our users as much as possible while performing your security research.
* If you access, store, modify or delete any of our data or data of our users, you must immediately delete any data you have stored and notify us of your actions by sending an email describing these actions to [security@appsignal.com](mailto:security@appsignal.com).
* You must prevent any harm to the availability, stability or security of our platform as much as possible while performing your security research.
* You must not create large numbers of accounts, send high volumes of traffic, or otherwise put our systems under load. Research that does so is disqualified, regardless of what it may find.
* You have not used the vulnerability for any purpose other than your participation in this program, and will not use the vulnerability for other purposes after filing your report.
* You keep confidential the details of the vulnerability and your report and have not published any information about the vulnerability in your report to third parties or publicly accessible sources.
* You are not employed by us or otherwise have a business relationship with us, nor have had any part in the development of the software that contains the vulnerability.
* You have reached the legally required age to be held responsible for your own actions under this program, or you can prove that you have been granted the required permission by a legal representative to participate in this program.
* You transfer any intellectual property rights that you created in relation to your security research of our software to AppSignal.

While you are performing your security research, our general Terms and Conditions still apply to you. These Terms and Conditions can be accessed here: [https://www.appsignal.com/terms](https://www.appsignal.com/terms)

If you act in accordance with this program and your report and security research meets its guidelines, we will not qualify your security research as a breach of our general Terms and Conditions and will not pursue civil or criminal action against you for performing this security research. Assessing whether your report and security research meets the guidelines of this program is at full discretion of AppSignal.

If you are in doubt whether certain actions violate this program, do not hesitate to reach out to us at [security@appsignal.com](mailto:security@appsignal.com).

This program can be amended by AppSignal at any time. The most recent version of the program shall be applicable to your security research and can be accessed at [https://appsignal.com/accounts](https://appsignal.com/accounts).
