generated: '2026-07-19' method: searched probe: true source: well-known/floy-security.txt docs: https://www.floy.com/vrp policy: - https://floy.com/vrp contact: - mailto:security@floy.com # Floy runs a Vulnerability Reward Program (bug bounty), active since January 2025, # with tiered monetary rewards. Self-hosted (no HackerOne/Bugcrowd/Intigriti platform). program: name: Floy Vulnerability Reward Program type: bug-bounty active_since: '2025-01' platform: self-hosted rewards: basis: CVSS severity range_eur: '275 - 2500' tiers: - {severity: Low, reward_eur: 275} - {severity: Exceptional, reward_eur: 2500} scope: - Any Floy-owned application or web service that handles reasonably sensitive user data - '*.floy.com domains' - On-premise deployments where the bug is caused by Floy out_of_scope: - Infrastructure hardening findings without a working exploit - Theoretical issues without a proof of concept - Third-party software vulnerabilities not caused by Floy configuration - Low-quality automated scanner output safe_harbor: true prohibited: - Phishing / social engineering - Physical intrusion - Denial of service evidence: - source: well-known/floy-security.txt kind: security.txt (previously harvested) - source: https://www.floy.com/vrp kind: vulnerability reward program page