Bug Bounty Program

Security is foundational to how we build Scape. We welcome security researchers to responsibly report vulnerabilities in our products and services, and we reward valid findings.

Scope

  • scape.app and its subdomains
  • The Scape desktop app
  • Our public APIs

Assets not explicitly listed above require prior authorization. Contact security@scape.app before testing anything else.

Rules

  • Do not access, modify, or expose user data.
  • Do not disrupt services or perform destructive testing.
  • No phishing, social engineering, or attacks against employees or customers.
  • Report vulnerabilities privately with a clear proof of concept and reproduction steps.
  • Give us reasonable time to remediate before any public disclosure.

Rewards

We classify each report as Critical, High, Medium, or Low severity based on its impact and exploitability, and rewards scale with severity. Depending on severity, rewards typically range from hundreds to thousands of dollars. Reward amounts are determined at our discretion, taking report quality into account. Duplicate or previously known issues may not qualify for rewards.

Safe harbor

Researchers who follow this policy and act in good faith will not face legal action from us for their authorized security testing.

How to report

Email your report to security@scape.app. Include the affected asset, a clear proof of concept, reproduction steps, and your assessment of the impact. We take every report seriously and acknowledge reports within 2 business days.

Scape AB · Luntmakargatan 26, 111 37 Stockholm, Sweden