We welcome good-faith reports that help protect testers, buyers, payouts, and customer research data. We do not run a paid bounty yet, but we acknowledge valid reports and credit researchers with consent.
www.9jatesters.com public application routes and unauthenticated API behavior.
Public authentication, order, signup, and API behavior without attempting credential theft or data exfiltration.
Authorization flaws that expose your own account data or demonstrably cross tenant boundaries in a safe proof.
Payment, webhook, cron, upload, and media-access issues that can be shown without harming real users.
Out of scope
Social engineering, phishing, spam, denial-of-service, or physical attacks.
Accessing, modifying, deleting, or publishing another person's data.
Automated high-volume scanning that degrades service availability.
Reports that only state missing certifications, missing bug bounty, or theoretical clickjacking where headers already deny framing.
Response targets
Email [email protected] with the subject "Security disclosure". Include the affected URL, impact, reproduction steps, and whether any data was accessed. We target acknowledgement within 24 hours, triage within 3 business days, and remediation for critical issues within 30 days where a safe temporary mitigation is not enough.
Please stop testing and notify us immediately if you encounter real user data, payment data, payment-verification data, private recordings, or admin-only information.