generated: '2026-08-30' method: searched source: https://home.trebel.io/bug-program name: TREBEL Music Bug Bounty Program description: >- TREBEL Music runs a first-party vulnerability disclosure and bug bounty program published at home.trebel.io/bug-program. It is self-hosted (submission web form) rather than run on HackerOne, Bugcrowd or Intigriti, and no RFC 9116 security.txt advertises it — the page was found by crawling the site's own sitemap.xml. program: present: true type: bug-bounty self_hosted: true platform: null policy_url: https://home.trebel.io/bug-program submission: web-form contact_email: null security_txt: false rewards: offered: true basis: >- "Rewards are provided at TREBEL's discretion based on the severity of the bug and the quality of the report." published_amounts: false eligibility: - Vulnerability must be verifiable and reproducible. - Vulnerability must not have been previously reported. - Researcher must comply with the published program guidelines. out_of_scope: - Privacy violations against TREBEL users. - Destruction or deletion of data / damage to resources. - Any activity causing lasting harm to TREBEL services. - Targeting TREBEL staff, investors, or physical property. safe_harbor: stated: true note: >- TREBEL states it will not pursue legal action against researchers who comply with the program, and will defend a compliant researcher if a third party initiates legal action over in-scope activity. x-evidence: fetched: '2026-08-30' probes: - url: https://home.trebel.io/bug-program status: 200 - url: https://home.trebel.io/.well-known/security.txt status: 404 - url: https://api.trebel.io/.well-known/security.txt status: 404 - url: https://home.trebel.io/security status: 404 - url: https://home.trebel.io/responsible-disclosure status: 404 gaps: - >- No /.well-known/security.txt on any TREBEL host. Publishing one (RFC 9116) with Policy: https://home.trebel.io/bug-program would make the program machine-discoverable.