Objective
To enhance the security of Helixbeat's digital assets by encouraging and rewarding the responsible disclosure of security vulnerabilities by external security researchers and ethical hackers.
Scope
This policy applies to all digital assets owned, operated, or maintained by Helixbeat, including websites, applications, APIs, and infrastructure.
Program Guidelines
1. Eligibility
- The program is open to individual researchers, teams, and organizations globally.
- Employees of Helixbeat, its affiliates, and subsidiaries are not eligible for rewards but are encouraged to report vulnerabilities through internal channels.
2. In-Scope Assets
- Helixbeat's main website (www.helixbeat.com)
- Mobile applications (iOS and Android)
- APIs and web services
- Other publicly accessible digital assets as specified on the Bug Bounty program page
3. Out-of-Scope Assets
- Third-party services and applications not owned by Helixbeat
- Denial of Service (DoS) attacks
- Social engineering attacks, including phishing
- Physical security vulnerabilities
4. Submission Guidelines
- Researchers must provide a detailed report including steps to reproduce the vulnerability, potential impact, and any suggested mitigation.
- Submissions should include relevant screenshots, videos, or code snippets to support the findings.
- Reports must be submitted through Helixbeat's official Bug Bounty email (info@helixbeat.com).
5. Responsible Disclosure
- Researchers must make a good faith effort to avoid privacy violations, data destruction, and service disruption.
- Vulnerabilities must not be publicly disclosed before they are resolved.
- Researchers should not exploit the vulnerability beyond the scope necessary to demonstrate its impact.
Reward Structure
1. Reward Criteria
- Rewards are based on the severity and impact of the vulnerability, quality of the report, and likelihood of exploitation.
- Helixbeat follows industry-standard vulnerability severity classifications such as CVSS (Common Vulnerability Scoring System).
2. Reward Tiers
- Low Severity: Up to $250
- Medium Severity: $250 - $1,000
- High Severity: $1,000 - $2,500
- Critical Severity: $2,500 and above
3. Reward Process
- Helixbeat will assess the submitted report and determine the severity and eligibility for a reward.
- Researchers will be notified of the assessment outcome and any applicable reward within 30 days of submission.
- Rewards will be paid in USD through a secure payment method agreed upon with the researcher.
Legal Safe Harbor
1. No Legal Action
- Researchers acting in good faith to find and report vulnerabilities are considered authorized and will not be subject to legal action by Helixbeat.
- This policy does not authorize any researcher to engage in illegal activity or violate any laws.
2. Scope of Authorization
- Researchers are authorized to conduct security research and testing on in-scope assets only.
- Activities beyond the scope outlined in this policy may lead to disqualification from the program and potential legal action.
Review and Amendments
1. Program Review
- The Bug Bounty program will be reviewed periodically to ensure it meets the evolving security needs of Helixbeat.
- Changes to the policy, scope, or reward structure will be communicated on the Bug Bounty platform and through official channels.
2. Researcher Feedback
- Feedback from the security community is valued and will be considered for improving the program.
Contact Information
For questions or further clarification regarding the Bug Bounty Program, researchers should contact Helixbeat's security team at info@helixbeat.com.
Shaping a Secure Future
This Bug Bounty Program Policy aims to foster a collaborative relationship with the security research community, providing clear guidelines and rewards for the responsible disclosure of vulnerabilities, and contributing to the overall security of Helixbeat's digital assets.