generated: '2026-08-29' method: searched source: https://www.syfe.com/bug-bounty probe: true program: Syfe Bug Bounty Programme platform: HackerOne policy: - https://www.syfe.com/bug-bounty - https://hackerone.com/syfe_bbp/ contact: [] contact_note: >- Syfe publishes no security@ address. Its own bug bounty page states that all vulnerability reports and test-credential requests must be submitted through the HackerOne programme, which is the sole intake channel. details: moved_to_hackerone: '2025-03' hall_of_fame: true reward_note: >- The Syfe security page advertises rewards up to US$1,000 plus Hall of Fame recognition; the bug bounty page defers current reward tiers and the in-scope/out-of-scope asset list to the HackerOne programme page. out_of_scope: - Network-level denial of service (DoS/DDoS) - Low-severity findings from automated scanners (e.g. Hardenize, Security Headers) - Content injection - CSRF with minimal impact - Missing cookie flags on non-sensitive cookies - UI/UX bugs - 401 injection - Stack traces - Banner grabbing - Missing X-Frame-Options headers - Cross-site tracing - Content-Security-Policy unsafe-inline - User enumeration - Email spoofing / SPF misconfiguration - Open redirect via Host header evidence: - source: https://www.syfe.com/bug-bounty kind: disclosure-page http_status: 200 fetched: '2026-08-29' - source: https://www.syfe.com/security kind: security-page http_status: 200 fetched: '2026-08-29' - source: https://hackerone.com/syfe_bbp kind: bug-bounty-platform http_status: 200 fetched: '2026-08-29' - source: https://www.syfe.com/.well-known/security.txt kind: security-txt http_status: 200 note: >- Not a document. www.syfe.com is a Webflow site whose catch-all answers HTTP 200 with the 131,618-byte "Not Found" page for every unmatched path, including every /.well-known/ path. No RFC 9116 security.txt is served.