generated: '2026-07-19' method: searched probe: false source: https://infstones.com/bug-bounty-program policy: - https://infstones.com/bug-bounty-program - https://infstones.com/terms/bug-bounty-program-terms-and-conditions contact: - https://infstones.com/bug-bounty-program program: type: self-hosted platform: null third_party: false submission: Web form on the bug bounty page (name, email, category, summary, PoC, attachments) scope_in: - infstones.com - app.infstones.com - fastapi.infstones.com scope_out: Any InfStones domain/property not explicitly listed rewards_disclosed: false evidence: - source: https://infstones.com/bug-bounty-program kind: bug-bounty-page keywords: [bug bounty, vulnerability, responsible disclosure, in-scope] - source: https://infstones.com/security kind: security-policy-page notes: >- InfStones runs a self-hosted bug bounty / responsible-disclosure program with a submission form and defined in-scope domains. No third-party platform (HackerOne/Bugcrowd/Intigriti) and no reward tiers are published. No RFC 9116 /.well-known/security.txt is served (host paths return the SPA shell, not a security.txt document).