<aside> πŸ›‘οΈ

Help us keep Birch secure and get rewarded for your findings.

</aside>

<aside> πŸ“§

Report To

[email protected]

</aside>

<aside> ⏱️

Response Time

5 business days

</aside>

<aside> πŸ’°

Rewards

$50 – $500

</aside>


1. Introduction

At Birch, we take security and privacy very seriously. We know that maintaining the trust of our B2B partners and customers is critical to our mission of automating marketing technology. If you believe you have found a security vulnerability that affects Birch, please report it to us.

Reports that fall within the scope of the Birch Bug Bounty Program are eligible for a reward. We appreciate your efforts in helping protect customer trust and making Birch more secure.


2. Scope

<aside> βœ…

In Scope

<aside> 🚫

Out of Scope


3. Rewards

We award bounties based on severity and business impact of the vulnerability.

<aside> πŸ’΅

How bounties are determined: Rewards are based on severity, report quality, and business impact, and may be adjusted at Birch’s sole discretion. Final amounts are not subject to negotiation.

</aside>

<aside> πŸ”΄

Critical β€” $300–$500

Remote code execution, authentication bypass, full database access, significant data breach potential

</aside>

<aside> 🟠

High β€” $150–$300

Stored XSS with significant impact, privilege escalation, access to other users’ sensitive data

</aside>

<aside> 🟑

Medium β€” $75–$150

Reflected XSS, CSRF on sensitive actions, information disclosure of non-critical data

</aside>

<aside> βšͺ

Low β€” $25–$75

Minor security issues with limited impact, requires unlikely user interaction

</aside>

Reward Factors

Increases reward:

Decreases reward:


4. Rules of Engagement

<aside> β›”

Do NOT (Strictly Prohibited):

<aside> βœ…

</aside>