Rewards · US$ 50 – 2.500
Bug Bounty & Vulnerability Disclosure
The security of FuturaBroker and our developers is a priority. If you found a vulnerability, we want to know — this policy describes how to report it responsibly.
Rewards
Amounts in US$The reward varies according to the severity of the confirmed vulnerability.
US$ 50
US$ 50 – 250
US$ 250 – 1.250
US$ 1.250 – 2.500
See the guidelines below for the full breakdown.
Scope
In scope: the FuturaBroker platform, the Futura Broker API and this developer portal. Out of scope: social engineering, physical attacks, DoS/DDoS and automated scanner reports without proof of impact.
Safe Harbor
We will not take legal action against researchers who follow this policy and act in good faith. If you have any doubt about the scope, ask through the report form below.
Do
- Provide clear reproduction steps and a proof of concept.
- Use only your own test accounts and data.
- Give a reasonable time to fix before disclosing.
Don't
- Access, modify or exfiltrate other users' data.
- Degrade the availability of the services.
- Exploit the flaw beyond what is needed to demonstrate it.
Submit a report
Fill in the fields below — the report goes straight to our security team, and we reply to the email you provide.