This Bug Bounty Policy outlines the rules for security researchers who discover and report vulnerabilities in Spencer's Website. We encourage responsible disclosure and offer recognition for valid reports.
1. Overview
We value the security community's help in identifying and fixing vulnerabilities. This policy provides guidelines for responsible disclosure and explains our commitment to not take legal action against researchers who follow these guidelines.
2. Eligibility
This policy applies to:
- Security researchers
- White hat hackers
- Academic researchers
- Anyone who discovers a security vulnerability
3. Scope
The following systems are in scope for this policy:
- Main website: thespencerwebsite.com
- User authentication: Login, registration, password reset
- Account management: Settings, profile, subscriptions
- API endpoints: All public and authenticated API endpoints
- Payment processing: Integration with Stripe (within our control)
- AI features: AI Assistant and related functionality
- Community features: Yaps chat, Smail, forums
Vulnerability types we're interested in:
- Authentication bypass
- Privilege escalation
- SQL injection
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Information disclosure
- Remote code execution
- Business logic vulnerabilities
4. Out of Scope
The following are out of scope:
- Third-party services: Stripe, Groq, Google services (report directly to them)
- Third-party games: Embedded games (report to game developers)
- Physical security: Our offices, data centers (not applicable for web-only)
- Social engineering: Phishing tests against our staff
- DDoS attacks: Any testing that degrades service availability
- Spam: Sending unsolicited emails to our users
5. Rules of Engagement
To qualify for safe harbor, you must:
- Report responsibly: Submit vulnerability reports through proper channels
- No exploitation: Do not access, modify, or delete data that is not your own
- No disruption: Do not degrade service availability or impact other users
- No PII access: Do not access personally identifiable information of other users
- Be patient: Give us reasonable time to fix vulnerabilities before disclosure
- Use test accounts: If testing requires authentication, use your own account
6. Safe Harbor
We commit to:
- No legal action: We will not pursue legal action against researchers who follow these guidelines
- No account termination: We will not terminate accounts for security research conducted in good faith
- Recognition: We will acknowledge valid reports (with your permission)
Safe harbor applies if you:
- Follow the rules of engagement
- Report the vulnerability before disclosing it publicly
- Give us reasonable time to fix the issue (typically 90 days)
- Do not use the vulnerability for malicious purposes
7. Submission Process
7.1 How to Report
Send vulnerability reports to:
Email: support@thespencerwebsite.com
Subject line: "Security Vulnerability Report"
7.2 What to Include
Your report should include:
- Description of the vulnerability
- Steps to reproduce (if applicable)
- PoC (proof of concept) if possible
- Impact assessment
- Suggested fix (optional)
7.3 PGP Key
For sensitive reports, you can encrypt your message using our PGP key (contact us to obtain our public key).
8. Rewards
8.1 Current Status
We do not currently offer monetary bounties. This is a recognition-only program.
8.2 Recognition
For valid reports, we may:
- List you in our security hall of fame (with your permission)
- Send you a certificate of recognition
- Offer a free subscription upgrade (if applicable)
- Provide public acknowledgment of your contribution
8.3 Future Bounties
We may introduce monetary bounties in the future. This policy will be updated if bounties become available.
9. Contact
For security vulnerability reports:
Email: support@thespencerwebsite.com
Subject line: "Security Vulnerability Report"