generated: '2026-08-11' method: searched probe: true source: https://www.thordata.com/security-vulnerabilities-reward-program note: >- Found via the sitemap, not via any conventional path. probe-security-programs.py reported vdp=none because Thordata serves no /.well-known/security.txt and none of the standard disclosure URLs (/security, /responsible-disclosure, /vulnerability-disclosure) exist. The program is real and paid, it is just undiscoverable by machine. program: name: Thordata Security Vulnerability Reward Program type: self-hosted bug bounty platform: null url: https://www.thordata.com/security-vulnerabilities-reward-program policy: - https://www.thordata.com/security-vulnerabilities-reward-program contact: - security@thordata.com scope: in_scope: - thordata.com and its pages, including dashboard.thordata.com - services and infrastructure explicitly listed on the program page out_of_scope: - internal or related services not explicitly named - any system requiring prior approval before testing qualifying: - Cross-Site Scripting (reflected, stored and DOM-based) - CSRF and clickjacking - Authentication and authorization flaws (auth bypass, session management, IDOR, privilege escalation) - Remote Code Execution on production servers - Data leakage or unauthorized access non_qualifying: - Denial of Service - UI/UX issues with no security impact - Theoretical, non-exploitable issues - Duplicate reports rewards: currency: USD tiers: - {severity: low, min: 100, max: 300, examples: 'XSS, CSRF, misconfigurations'} - {severity: medium, min: 300, max: 1000, examples: 'RCE affecting SDK users, data extraction'} - {severity: high, min: 1000, max: 2000, examples: 'production RCE, authentication bypass'} claim_window: rewards expire if unclaimed within 2 months disclosure: embargo_days: 60 terms: >- Reporters must not publicly disclose or share vulnerability details until at least 60 days after the vulnerability is confirmed. acknowledgement_sla: 3-5 business days gaps: - >- No /.well-known/security.txt on any host (see well-known/thordata-well-known.yml). RFC 9116 is the machine-readable front door for exactly this program; publishing one would take a single file naming Contact, Policy and Preferred-Languages. - >- The program page is not linked from the documentation host (doc.thordata.com) or surfaced in either llms.txt, so an agent reading the docs has no path to it. evidence: - {source: 'https://www.thordata.com/security-vulnerabilities-reward-program', http_status: 200, kind: disclosure-page} - {source: 'https://www.thordata.com/sitemap.xml', http_status: 200, kind: discovery} - {source: 'https://www.thordata.com/.well-known/security.txt', http_status: 404, kind: security.txt-absent}