Bug Bounty Program
We value the security and functionality of our platform and appreciate the community's help in identifying issues. Our bug bounty program rewards users who responsibly report bugs that affect the functionality, security, or user experience of Outfox Stories.
Reward
US$20 cash for each valid bug report. Payment will be made within 30 days of bug verification.
Eligible Bugs
We're interested in bugs that impact:
- Security vulnerabilities - XSS, SQL injection, authentication bypass, data exposure, etc.
- Functional bugs - Features that don't work as intended or prevent normal use of the site
- Data integrity issues - Data loss, corruption, or incorrect calculations
- Payment processing errors - Issues with subscriptions, support payments, or billing
- Significant UI/UX issues - Problems that severely impact usability or accessibility
- Performance issues - Severe slowdowns or crashes that affect user experience
How to Report
To submit a bug report:
- Email your report to support@outfoxstories.com with subject line "Bug Report"
- Include a clear description of the bug and its impact
- Provide detailed steps to reproduce the issue
- Attach screenshots or screen recordings if applicable
- Include your browser version, operating system, and device type
- If reporting a security vulnerability, please do not disclose it publicly
Program Terms
- Only the first person to report a specific bug is eligible for the reward
- Bugs must be previously unknown to our team
- You must not exploit the bug for personal gain or to harm other users
- Do not perform any attack that could harm the reliability or integrity of our services
- Do not access or modify other users' data without permission
- We reserve the right to determine bug validity and reward eligibility
- Minor issues like typos or minor cosmetic problems are not eligible for rewards
- Bugs in third-party services or libraries are not eligible unless they directly impact our platform
Responsible Disclosure
We ask that you give us reasonable time to address the issue before making any information public. We aim to resolve critical security issues within 48 hours and other bugs within 7-14 days, depending on severity.