Bug Bounty Policy

Rules and rewards for reporting security vulnerabilities.

Updated May 5, 2026 Version 1.0

This Bug Bounty Policy outlines the rules for security researchers who discover and report vulnerabilities in Spencer's Website. We encourage responsible disclosure and offer recognition for valid reports.

Current status: We do not currently offer monetary bounties. This policy outlines our safe harbor provisions and recognition program.

1. Overview

We value the security community's help in identifying and fixing vulnerabilities. This policy provides guidelines for responsible disclosure and explains our commitment to not take legal action against researchers who follow these guidelines.

2. Eligibility

This policy applies to:

  • Security researchers
  • White hat hackers
  • Academic researchers
  • Anyone who discovers a security vulnerability

3. Scope

The following systems are in scope for this policy:

  • Main website: thespencerwebsite.com
  • User authentication: Login, registration, password reset
  • Account management: Settings, profile, subscriptions
  • API endpoints: All public and authenticated API endpoints
  • Payment processing: Integration with Stripe (within our control)
  • AI features: AI Assistant and related functionality
  • Community features: Yaps chat, Smail, forums

Vulnerability types we're interested in:

  • Authentication bypass
  • Privilege escalation
  • SQL injection
  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF)
  • Information disclosure
  • Remote code execution
  • Business logic vulnerabilities

4. Out of Scope

The following are out of scope:

  • Third-party services: Stripe, Groq, Google services (report directly to them)
  • Third-party games: Embedded games (report to game developers)
  • Physical security: Our offices, data centers (not applicable for web-only)
  • Social engineering: Phishing tests against our staff
  • DDoS attacks: Any testing that degrades service availability
  • Spam: Sending unsolicited emails to our users

5. Rules of Engagement

To qualify for safe harbor, you must:

  • Report responsibly: Submit vulnerability reports through proper channels
  • No exploitation: Do not access, modify, or delete data that is not your own
  • No disruption: Do not degrade service availability or impact other users
  • No PII access: Do not access personally identifiable information of other users
  • Be patient: Give us reasonable time to fix vulnerabilities before disclosure
  • Use test accounts: If testing requires authentication, use your own account

6. Safe Harbor

We commit to:

  • No legal action: We will not pursue legal action against researchers who follow these guidelines
  • No account termination: We will not terminate accounts for security research conducted in good faith
  • Recognition: We will acknowledge valid reports (with your permission)

Safe harbor applies if you:

  • Follow the rules of engagement
  • Report the vulnerability before disclosing it publicly
  • Give us reasonable time to fix the issue (typically 90 days)
  • Do not use the vulnerability for malicious purposes

7. Submission Process

7.1 How to Report

Send vulnerability reports to:

Email: support@thespencerwebsite.com

Subject line: "Security Vulnerability Report"

7.2 What to Include

Your report should include:

  • Description of the vulnerability
  • Steps to reproduce (if applicable)
  • PoC (proof of concept) if possible
  • Impact assessment
  • Suggested fix (optional)

7.3 PGP Key

For sensitive reports, you can encrypt your message using our PGP key (contact us to obtain our public key).

8. Rewards

8.1 Current Status

We do not currently offer monetary bounties. This is a recognition-only program.

8.2 Recognition

For valid reports, we may:

  • List you in our security hall of fame (with your permission)
  • Send you a certificate of recognition
  • Offer a free subscription upgrade (if applicable)
  • Provide public acknowledgment of your contribution

8.3 Future Bounties

We may introduce monetary bounties in the future. This policy will be updated if bounties become available.

9. Contact

For security vulnerability reports:

Email: support@thespencerwebsite.com

Subject line: "Security Vulnerability Report"