BlueMail Security · Bug Bounty

Find a vulnerability, earn a bounty.

Security researchers make BlueMail safer for everyone. If you find a vulnerability in our apps or infrastructure, report it responsibly and we'll reward you based on its severity.

In scope

What we're looking for.

Cross-site scripting (XSS)

Injected scripts that execute in another user's session, stored or reflected.

Cross-site request forgery (CSRF)

Requests that perform sensitive actions on behalf of a user without their intent.

SQL injection

Any input path that reaches a query and lets you read or modify data you shouldn't.

Authentication & authorization flaws

Bypassing login, escalating privileges or accessing another account's data.

Remote code execution

Executing code on BlueMail servers or inside the apps through crafted input.

Something else severe?

If it puts user data or accounts at real risk, we want to hear about it. When in doubt, report it.

Rewards

Paid by severity.

Severity is assessed with you during triage, based on impact and exploitability.

Low Minor issues with limited impact Up to $200
Medium Real impact, limited reach or preconditions $200 to $500
High Serious impact on user data or accounts $500 to $1,000
Critical Widespread impact, RCE or full account takeover $1,000 to $3,000

Program rules

  • Follow responsible disclosure: report to us first and give us time to fix.
  • No public disclosure before a fix is released.
  • Do not interact with real end users or their data.
  • No social engineering of BlueMail staff or users.
  • No automated scanning, brute force or denial-of-service attacks.

Eligibility

  • You are the first to report the issue.
  • Your report includes clear, reproducible steps or a proof of concept.
  • You are available for follow-up questions while we verify and fix.
  • You are not a BlueMail employee or an immediate family member of one.

Out of scope

  • Descriptive error messages or stack traces without a demonstrated impact
  • Clickjacking on pages with no sensitive actions
  • Attacks that require physical access to a victim's device
  • Issues already reported by someone else or already known to us

Found something?

Email us a clear description, steps to reproduce, your impact assessment and proof-of-concept code where it helps. We respond to responsible-disclosure reports within one business day.

security@bluemail.me