generated: '2026-08-13' method: searched probe: true source: https://www.superside.com/bug-bounty-program-policy program: Superside Bug Bounty Program self_managed: true platform: none platform_note: >- Self-managed by email. No HackerOne / Bugcrowd / Intigriti listing was found for Superside. (The bugcrowd.com/intercom reference on help.superside.com belongs to Intercom, the help-center vendor, not to Superside.) policy: - https://www.superside.com/bug-bounty-program-policy contact: - mailto:security@superside.com security_page: https://www.superside.com/security safe_harbor: true safe_harbor_text: >- "Superside will not engage in legal action against individuals who submit vulnerability reports" provided testing causes no harm, stays in scope, follows local law, and avoids premature public disclosure. scope: in_scope: - https://app.supersidestaging.com/ - https://internal.supersidestaging.com/ - https://admin.supersidestaging.com/ - https://api.supersidestaging.com/ - https://api-internal.supersidestaging.com/ out_of_scope: - https://www.superside.com/ - https://app.superside.com/ scope_note: >- Testing is prohibited on the production environment; all in-scope targets are on the supersidestaging.com staging domain. rewards: currency: USD bands: - severity: critical min: 1500 max: 2000 - severity: high min: 750 max: 1000 - severity: medium min: 200 max: 400 - severity: low min: 0 max: 0 first_reporter_only: true response_sla: first_response: 2-5 business days triage: 2-5 business days payout: middle of the next calendar month security_txt: false security_txt_note: >- Superside serves no /.well-known/security.txt on any first-party host (all 404 — see well-known/superside-well-known.yml). The disclosure program is discoverable only from the HTML security page. Publishing an RFC 9116 security.txt pointing at security@superside.com and the bug-bounty policy URL is the single cheapest improvement available here. evidence: - source: https://www.superside.com/security http_status: 200 kind: security-page keywords: [bug bounty program policy, soc 2 type ii, incident response plan] - source: https://www.superside.com/bug-bounty-program-policy http_status: 200 kind: disclosure-policy keywords: [security@superside.com, safe harbor, scope, rewards] - source: https://www.superside.com/.well-known/security.txt http_status: 404 kind: security.txt keywords: [] fetched: '2026-08-13'