StriseWiki
Technology

Strise Bug Bounty Program

Strise is dedicated to providing a secure and reliable SaaS platform for our customers. To continuously enhance the security of our platform, we are introducing the Strise Bug Bounty Program, which invites security researchers to identify and report potential vulnerabilities in our system.

We encourage responsible disclosure of security vulnerabilities and will reward researchers based on the severity and impact of the identified issues. Keep in mind that our main focus is to protect our customers' data and privacy.

Rewards

Bounties for qualifying submissions will range from $5 to $1,000, depending on the severity and impact of the vulnerability:

  • Low severity: $5 – $50
  • Medium severity: $51 – $250
  • High severity: $251 – $500
  • Critical severity: $501 – $1,000

Please note that the final decision on the reward amount will be at the discretion of the Strise security team.

Reporting Guidelines

To report potential security vulnerabilities, please email our security team at security@strise.ai.

In your email, include the following information:

  1. A detailed description of the vulnerability, including the steps required to reproduce it
  2. The potential impact of the vulnerability and suggested remediation steps, if any
  3. Your contact information

We are receiving an increasing number of AI-generated bug bounty reports, and as a result not all reports will be answered. Reports describing the same underlying issue are grouped, and credit and any reward go to whoever reported the issue first. Duplicate reports will not receive a response.

Access to Systems

Strise does not provide researcher accounts, test tenants, trial access, or isolated test environments for security testing. There is no self-service signup, and requests for platform access for research purposes will not be granted. Testing is limited to what is reachable without authenticated access to the Strise platform. Please do not email us to request access — such requests will not receive a response.

Rules and Scope

To participate in the Strise Bug Bounty Program, you must adhere to the following rules:

  1. Do not perform any actions that could lead to data exfiltration, service degradation, or unauthorised access to customer data.
  2. Avoid using automated scanning tools, as they may lead to false positives and unwanted system disruptions.
  3. Do not perform or report social engineering attacks, spam, or denial-of-service attacks.
  4. Disclose vulnerabilities exclusively to the Strise security team and refrain from disclosing them publicly before Strise has had a chance to review and remediate the issue.

By participating in the Strise Bug Bounty Program, you agree to comply with all applicable laws and regulations. Strise reserves the right to disqualify any participant who violates these rules, as well as to modify the terms of the program at any time.

Last updated on

On this page