Aller au contenu
Skip to main content
Responsible Disclosure • Security

Bug Bounty
Responsible Disclosure & Rewards

Responsible disclosure program: clear scope, clean rules, and recognition for the community.

Overview & goals

ForenShield provides a structured channel to report discovered vulnerabilities. Goal: fix issues quickly, improve resilience, and recognize the community's contribution.

Responsible disclosure means mutual respect, confidentiality and cooperation on mitigation. Until the full financial program launches (planned for 2027), symbolic or public recognition may be granted depending on impact.

Scope

In scope

  • Official domains: forenshield.com and subdomains.
  • Documented public UI and APIs.
  • Explicitly testable demo/sandbox environments.

Out of scope

  • DoS/DDoS, intentional denial of service.
  • Social engineering (employees/customers/partners).
  • Access to third parties, physical systems, or unlisted infrastructure.
  • Tests exposing personal data outside a controlled setting.

Golden rule: Proof, not damage. We prefer a minimal proof-of-concept and a clear report over a "heavy-handed test".

Reporting process

Send your reports to [email protected] with a clear description, reproduction steps (PoC), estimated impact and remediation ideas.

Quick template (copyable):

Subject: [BugBounty] <quick summary>

Hello,

Scope: https://forenshield.com/…
Type: (XSS / IDOR / SSRF / auth / …)
Impact: (What it actually allows)
Steps: 1) … 2) … 3) …
PoC: (minimal request / payload)
Mitigation: (fix idea if you have one)

Thanks.
Open an email

Rewards & recognition

Public recognition (with agreement), badges, Hall of Fame. Financial scale published with the full program in 2027. Severity, report quality and cooperation determine the recognition granted.

Official contact

Reports: [email protected]

DPO / GDPR rights: [email protected]

Technical examples (logs & payloads)

Hex payload: 46 4F 52 33 4E 7B 48 45 58 5F 46 4C 41 47 7D

Observed bytes: 70,79,82,51,78,95,67,72,75

Last updated: December 21, 2025

ForenCTF

7 flags
0 / 7 found
Encoded comment (Base64 of HEX)
String encoded inside a source comment.
Attempts: 0
Encoded comment (Base64 of HEX)
Not found
Attempts: 0
Data attribute (Base64)
Not found
Attempts: 0
Scattered hex
Not found
Attempts: 0
Caesar shift (+5)
Not found
Attempts: 0
Script char codes
Not found
Attempts: 0
MD5 preimage
Not found
Attempts: 0
Math → ASCII
Not found
Attempts: 0
Sign up (prerequisite)