Bugcrowd strives to create a safe, inclusive and positive environment for the mutual benefit of Researchers and Customers alike, allowing for collaborative engagement in the pursuit of a safer Internet.
The Platform Behavior Standards are in place to help Researchers better understand unacceptable issues and behaviors on our platform, and which measures are taken when we become aware of an incident.
Behavior Type | Severity Value | Definitions & Example Behaviors |
---|---|---|
Disruptive Behavior | 1 |
|
Aggressive Behavior | 1 |
|
Out of Scope | 1 |
|
Out of Band Contact | 1 |
|
Duplicate Abuse | 2 |
|
Program Disclosure | 2 |
|
Disclosure Threat | 3 |
|
Unauthorized Disclosure | 4 |
|
Abusive Behavior & Harassment | 4 |
|
Extortion Threat | 4 |
|
Ban Dodge | 5 |
|
These Enforcement Actions apply to all persons entering our platform or engaging in communication with customers and Bugcrowd employees.
Total Severity Value | Enforcement Measure | Action Definition |
---|---|---|
1 | Coaching Message | The researcher receives a coaching message from Bugcrowd explaining what behavior is unacceptable, provided guidance for correcting the behavior going forward, and how many points they have. |
2 | Warning | The researcher receives a warning messaged explaining what behavior is unacceptable, and an outline of what will happen if they have another incident and how many points they have. |
3 | Final Warning | The researcher receives a final warning messaged explaining what behavior is unacceptable, the next incident will result in Temporary Suspension or Platform Ban, and how many points they have. |
4 | Temporary Suspension | The researcher receives a messaging outlining how long they are temporarily suspended from the platform and how many points they have. |
5+ | Platform Ban | The researcher has 5+ points and is removed from the platform with messaging outlining why they have been banned. |
Please be aware; Bugcrowd retains the ability to adjust the severity of an enforcement measure depending on the gravity of the infraction. Additionally, depending on the nature of the infraction, Bugcrowd may impose further enforcement penalties such as extended ban durations, immediate program removal, and permanent removal from the Bugcrowd platform.
Other violations of this Code of Conduct, the Standard Disclosure Terms, the Terms of Service, or other applicable terms and customer program briefs can result in enforcement actions as well, including a warning and/or removal of access to elements of the Bugcrowd platform on a temporary or permanent basis depending on the severity of the violation. In some instances, an offender will be removed from Bugcrowd bounties or from the Bugcrowd community entirely.
All policy enforcement and eligibility decisions are made entirely at the discretion of Bugcrowd. Decisions are final and considered private matters between Bugcrowd’s team members and the individuals(s) involved. If you have any questions about a recent action taken on your account, please contact Bugcrowd Support for details.
WHAT HAPPENS IF YOU RECEIVE AN ENFORCEMENT ACTION
Bugcrowd counts 1-mark and 2-mark incidents toward Total Marks for a rolling 12-month period. After 12 months, 1-mark and 2-mark incidents are considered expired and are only included in incident reviews if a pattern of behavior precedes this new incident. 4- and 5-mark incidents never expire and are considered active for the purpose of a new incident review. Additionally, program invitations may be revoked at the discretion of Customers and/or Bugcrowd based on the severity of the incident(s).
If a researcher is banned from the platform, they may request a Reinstatement Review after 1-full year. Bugcrowd will provide the Researcher with an update once the Reinstatement Review is completed. Depending on the severity of previous incidents, we may not accept a Researcher’s Reinstatement, and the ban may remain in place. Contact Support Portal to request a Reinstatement Review.
HELP US, HELP YOU
If you observe a fellow Researcher violating our Code of Conduct and/or exhibiting malicious behaviors that are not conducive to building a safe and positive professional environment, please report it to the Bugcrowd Support Team at Support Portal. We are grateful for your support in fortifying our community’s experience.
TERMS & CONDITIONS AND STANDARD DISCLOSURE POLICY
We have a Terms and Conditions document describing your (and our) behavior and rights related to content, privacy, and laws. To participate in Bugcrowd programs and offerings you must agree to abide by our Terms and Conditions and the Standard Disclosure Terms.
Get Started with Bugcrowd
Every minute that goes by, your unknown vulnerabilities leave you more exposed to cyber attacks.