Report a
security issue.
Our commitments
What you'll get back from us.
A human on our security rota picks up every report — no autoresponder walls.
Severity, reproduction, and rough remediation timeline shared with the reporter.
Named acknowledgment on our security hall of fame page after the fix ships (or immediately, if you prefer to stay anonymous).
Good-faith research that follows this policy will not be pursued under CFAA, CMA, DMCA, or their local equivalents.
What we want you to test.
- lepta.dev and any subdomain we operate (marketing, app, api, status, docs).
- The Lepta QA REST API and outgoing webhooks.
- Any Lepta-authored open-source runner or SDK we publish.
- Client-side JavaScript we ship on our own domains.
Please don't do this.
- Denial-of-service or resource-exhaustion attacks.
- Physical attacks against our office, staff, or property.
- Social engineering of Lepta employees or contractors.
- Testing that impacts other customers' workspaces — use your own workspace or a scratch account.
- Automated scanner reports without a working proof-of-concept.
- Missing security headers on pages that don't handle sensitive data.
- Rate-limit-only findings that require abusing a valid account.
- Reports about email spoofing on domains we don't send from.
- Third-party integrations (GitHub, Zoom, Slack, etc.) — please report those to the vendor.
Rewards
Bounty bands, paid in credits.
Indicative ranges paid in Lepta QA platform credits. Final amounts reflect severity, quality of the report, and business impact. Credits apply to any paid plan, credit-pack top-up, or overage on your own workspace — or you can gift them.
| Severity | Reward | Example |
|---|---|---|
| Critical | 50,000 – 250,000 credits | RCE, tenant isolation break, workspace-wide data exposure. |
| High | 25,000 – 75,000 credits | Authentication bypass, IDOR on a critical resource, stored XSS with session takeover. |
| Medium | 7,500 – 25,000 credits | Reflected XSS with limited impact, CSRF on a state-changing route. |
| Low | 2,500 – 7,500 credits | Missing hardening, information leaks without direct exploit path. |
Credits are non-transferable to cash and expire 12 months after issue. Rewards are discretionary and paid at Lepta's sole discretion.
Ready to report?
Send us your finding through the secure feedback widget. Include a proof-of-concept and impact assessment where possible — you can attach screenshots and recordings right in the form.
FAQ
Common questions.
How do I send you a report?+
Do you pay bounties?+
Can I test in production?+
How long do I need to keep the finding private?+
Ready to ship
without the dread?
Free to start, no credit card. Spin up your first project and invite your team in minutes.