<aside> π‘οΈ
Help us keep Birch secure and get rewarded for your findings.
</aside>
<aside> π§
Report To
</aside>
<aside> β±οΈ
Response Time
5 business days
</aside>
<aside> π°
Rewards
$50 β $500
</aside>
At Birch, we take security and privacy very seriously. We know that maintaining the trust of our B2B partners and customers is critical to our mission of automating marketing technology. If you believe you have found a security vulnerability that affects Birch, please report it to us.
Reports that fall within the scope of the Birch Bug Bounty Program are eligible for a reward. We appreciate your efforts in helping protect customer trust and making Birch more secure.
<aside> β
In Scope
<aside> π«
Out of Scope
We award bounties based on severity and business impact of the vulnerability.
<aside> π΅
How bounties are determined: Rewards are based on severity, report quality, and business impact, and may be adjusted at Birchβs sole discretion. Final amounts are not subject to negotiation.
</aside>
<aside> π΄
Critical β $300β$500
Remote code execution, authentication bypass, full database access, significant data breach potential
</aside>
<aside> π
High β $150β$300
Stored XSS with significant impact, privilege escalation, access to other usersβ sensitive data
</aside>
<aside> π‘
Medium β $75β$150
Reflected XSS, CSRF on sensitive actions, information disclosure of non-critical data
</aside>
<aside> βͺ
Low β $25β$75
Minor security issues with limited impact, requires unlikely user interaction
</aside>
Increases reward:
Decreases reward:
<aside> β
Do NOT (Strictly Prohibited):
<aside> β
</aside>