Rewards · US$ 50 – 2.500

Bug Bounty & Vulnerability Disclosure

The security of FuturaBroker and our developers is a priority. If you found a vulnerability, we want to know — this policy describes how to report it responsibly.

Rewards

Amounts in US$

The reward varies according to the severity of the confirmed vulnerability.

Low

US$ 50

Medium

US$ 50 – 250

High

US$ 250 – 1.250

Critical

US$ 1.250 – 2.500

See the guidelines below for the full breakdown.

Scope

In scope: the FuturaBroker platform, the Futura Broker API and this developer portal. Out of scope: social engineering, physical attacks, DoS/DDoS and automated scanner reports without proof of impact.

Safe Harbor

We will not take legal action against researchers who follow this policy and act in good faith. If you have any doubt about the scope, ask through the report form below.

Do

  • Provide clear reproduction steps and a proof of concept.
  • Use only your own test accounts and data.
  • Give a reasonable time to fix before disclosing.

Don't

  • Access, modify or exfiltrate other users' data.
  • Degrade the availability of the services.
  • Exploit the flaw beyond what is needed to demonstrate it.

Submit a report

Fill in the fields below — the report goes straight to our security team, and we reply to the email you provide.