Skip to main content
Home / Security
Responsible Disclosure  ·  Updated May 2026

Found a bug? We want to hear from you.

Report a real security issue responsibly and earn a public TrueCert Security Researcher credential. No monetary bounty, but a verifiable badge you can link from your CV or LinkedIn alongside our other professional credentials.

TL;DR: We don't pay cash for vulnerability reports. We do publicly acknowledge legitimate researchers with a verifiable TrueCert Security Researcher credential. Report bugs to [email protected].

How our recognition program works

Most "bug bounty" programs reward researchers with cash. We do something different: legitimate findings earn a public, verifiable TrueCert Security Researcher credential, similar in structure to the assessment certificates we issue across the platform. The credential is Open Badges 2.0 compliant, can be linked from LinkedIn or your CV, and includes a public verification URL employers can check.

The goal is to reward serious researchers with portable, real credibility, not a one-time cash payout. For junior security researchers building a portfolio toward SOC, AppSec, or pentesting roles, a verified finding at a real production company is genuinely more useful than $50.

Recognition tiers

Tier Threshold Credential
Bronze 1 valid low-severity finding TrueCert Security Contributor
Silver 1+ medium-severity finding TrueCert Security Researcher
Gold 1+ high-severity finding or 3+ valid findings TrueCert Senior Security Researcher

In scope

We accept reports on exploitable issues that affect the security or integrity of TrueCert services. Common categories we acknowledge:

Out of scope

We do not acknowledge or accept reports on:

How to report

Send a detailed report to [email protected] including:

We aim to acknowledge initial reports within 10 business days. Verified findings are added to the public researcher list within 10 business days of remediation.

Rules of engagement

By submitting a report, you agree to:

Good-faith research under these rules will not result in legal action from TrueCert. Reports that violate these rules (especially extortion attempts) will be ignored, blocked, and where appropriate reported to the relevant authorities.

Researcher recognition

Verified security researchers are listed on our public acknowledgments page. Each entry includes the researcher's name or handle, the bug class, severity, and date.

View the TrueCert Security Researchers list →

Frequently asked questions

Do you pay cash bounties?

No. Verified findings earn a public TrueCert Security Researcher credential with a verifiable badge URL. We don't pay cash.

Will you acknowledge automated scanner output?

No. We require a written proof-of-concept demonstrating actual impact. "Missing security header" or "outdated library" reports without a working exploit are out of scope.

Can I report findings on Cloudflare, Stripe, or other vendors?

No. Those should be reported to the vendor directly. We only accept findings on services TrueCert operates.

How long until I'm listed publicly?

Initial acknowledgment within 10 business days. Public listing within 10 business days after the fix is deployed. We don't list researchers before remediation.