generated: '2026-07-17' method: searched probe: true source: https://airtime.com/en/legal/responsible-disclosure-and-bug-bounty-policy policy: - https://airtime.com/en/legal/responsible-disclosure-and-bug-bounty-policy contact: - https://help.airtimetools.com/hc/requests/new bug_bounty: platform: none self_managed: true discretionary_rewards: true scope: - airtimetools.com and subdomains - mmhmm.app and subdomains in_scope_vulnerabilities: - Authentication or Authorization flaws - Cross-site Scripting (XSS) - Cross-site Request Forgery (CSRF) - File inclusion - Open redirect - Server-side code execution - Injection flaws - Significant security misconfigurations notes: >- Airtime (successor to mmhmm) maintains a self-managed responsible-disclosure and bug-bounty policy. Reports are submitted via the help center request form (issue type "Security report"); no third-party platform (HackerOne/Bugcrowd/ Intigriti) is used. Rewards are discretionary. evidence: - source: https://airtime.com/en/legal/responsible-disclosure-and-bug-bounty-policy kind: disclosure-page