Bug Bounty Program
Help us keep Zof AI secure. Report vulnerabilities responsibly and earn rewards.
$5,000 - $15,000
Critical$1,000 - $5,000
High$250 - $1,000
Medium$50 - $250
Low
Reward Levels Priority
Send your report to security@zof.ai with detailed reproduction steps. We will respond within 48 hours.
$5,000 - $15,000
RCE, Auth bypass, Data breach
$1,000 - $5,000
SQLi, XSS (stored), SSRF
$250 - $1,000
CSRF, Info disclosure, Privilege escalation
$50 - $250
Open redirect, Clickjacking, Missing headers
In Scope
Testing Guidelines
Program Rules
- You must be 18 years or older
- You cannot be a current or former Zof AI employee
- You must not reside in a country under US sanctions
- Only test against your own accounts
- Do not access, modify, or delete other users' data
- Do not perform denial of service attacks
- Report vulnerabilities promptly and keep them confidential
- Social engineering attacks
- Physical security testing
- Third-party services and applications
- Spam or rate limiting issues
Found a Vulnerability?
Send your report to security@zof.ai with detailed reproduction steps. We will respond within 48 hours.
