generated: '2026-08-13' method: searched source: https://www.reviewtrackers.com/bug-bounty/ name: ReviewTrackers Vulnerability Disclosure and Bug Bounty description: >- ReviewTrackers runs a self-hosted bug bounty program with a published policy page, a named security contact, and an explicit in-scope target list that includes the production API host. There is no security.txt on any host — the policy is published only as an HTML page. program: type: self-hosted platform: null platform_note: Not run on HackerOne, Bugcrowd or Intigriti — ReviewTrackers accepts reports directly. rewards: true reward_detail: Monetary awards paid, amount dependent on severity. No published bounty table. policy: - https://www.reviewtrackers.com/bug-bounty/ contact: - security@reviewtrackers.com scope: in_scope: - target: reviewtrackers.com type: website - target: app.reviewtrackers.com type: website - target: admin.reviewtrackers.net type: website - target: api.reviewtrackers.com type: api - target: ReviewTrackers iOS application type: mobile - target: ReviewTrackers Android application type: mobile out_of_scope: - Any ReviewTrackers domain or property not named in the targets list. - Third-party services. - Signing up for new accounts or requesting free trials as part of testing. - Testing contact and feedback form functionality. focus_areas: - Unauthorized access to other users' data - SQL injection safe_harbor: published: true requirements: - Allow reasonable investigation time before public disclosure. - Do not access or modify other users' accounts or data without permission. - Do not violate privacy. - Do not exploit a discovered vulnerability beyond proof of existence. - Comply with applicable law. response_sla: null security_program: penetration_testing: Annual third-party penetration testing; certificate of results available on request via account manager. vulnerability_scanning: Daily comprehensive security scan with alerting on the application and website. password_storage: bcrypt cyber_insurance: true employee_screening: Background and reference checks, confidentiality agreements, recurring security training, 90-day password rotation. source: https://www.reviewtrackers.com/terms-service/security/ evidence: - source: https://www.reviewtrackers.com/bug-bounty/ kind: bug-bounty-policy http_status: 200 - source: https://www.reviewtrackers.com/terms-service/security/ kind: security-page http_status: 200 keywords: [bug bounty, penetration testing, bcrypt, cyber insurance] - source: https://api.reviewtrackers.com/.well-known/security.txt kind: security.txt http_status: 404 result: not served notes: - >- No RFC 9116 security.txt is served on any ReviewTrackers host. Publishing one at /.well-known/security.txt pointing Contact at security@reviewtrackers.com and Policy at the bug bounty page would make this program machine-discoverable.