Report security vulnerabilities or suggest improvements to SocNet Store and earn a reward. See what's in scope and how to submit a report.
Bug Bounty ProgramWhat we accept:vulnerabilities affecting user account security (authorization bypass, session theft, XSS, CSRF)bypassing payment logic (double charging, incorrect balance crediting, payment bypass)SQL injections, IDOR, leakage of others' dataAPI vulnerabilities (for resellers)What we DO NOT accept:vulnerabilities of social networks and third-party services (Instagram, TikTok, etc.)DDoS attacks, spam, brute forcesocial engineering of employeesabsence of security headers without real impactvulnerabilities requiring physical access to the user's deviceRules:do not disclose vulnerability details until it is fixeddo not harm other users' datause only your account for testingone vulnerability = one report, duplicates are not paidThe reward is determined individually based on the criticality and quality of the report. Priority is given to the first finder.Service improvement programWe are always open to ideas that will make the service more convenient.What interests us:new features in the personal account and on the websiteinterface improvements and convenience of placing ordersnew types of services or social networksAPI improvements and reseller panelany ideas that will save time for you and other clientsHow it works:describe the idea in as much detail as possible, with examples and screenshotswe review each proposal within 7 business daysupon implementation, the author receives gratitude and a bonus to their balanceWe do not guarantee the implementation of every idea, but each one is considered personally by the team.How to submit a report or proposal: click one of the buttons below. For authorized users, the contacts will be pulled automatically, guests can provide any email for communication.