Bug Bounty and Vulnerability Disclosure
Last updated: June 2026
eCourtDate runs an active bug bounty and responsible disclosure program. We are committed to addressing reported security issues quickly. We confirm and validate reports within 3 business days, and resolve validated reports within 10 business days.
If you believe you have found a security vulnerability in the eCourtDate platform, report it to security@ecourtdate.com. Include as much detail as possible, a clear description, reproduction steps, and a proof of concept, so we can validate the issue quickly.
Compensation
Compensation is based on the CVSS severity rating of a validated report.
| CVSS score | Rating | Reward (USD) |
|---|---|---|
| 0 | Informational / usability | $50 |
| 0.1 to 1.0 | Very low | $100 |
| 1.1 to 3.9 | Low | $500 |
| 4.0 to 6.9 | Medium | $2,500 |
| 7.0 to 8.9 | High | $5,000 |
| 9.0 to 10.0 | Critical | $10,000+ |
Security researchers
We provide professional security researchers a free developer account for testing. Email security@ecourtdate.com with a link to your professional profile (LinkedIn, GitHub, Bugcrowd, HackerOne, or similar). We do not provide accounts to anonymous users.
Scope
The scope is limited to technical vulnerabilities in the *.ecourtdate.com platform. Please do not attempt to compromise the safety or privacy of the people the platform serves. The chat widget is out of scope, as it is powered by a third party.
Out of scope
- Clickjacking on pages with no sensitive actions.
- Cross-site request forgery (CSRF) on unauthenticated forms or forms with no sensitive actions.
- Attacks requiring man-in-the-middle or physical access to a user's device.
- Previously known vulnerable libraries without a working proof of concept.
- CSV injection without demonstrating a vulnerability.
- Missing best practices in SSL/TLS configuration.
- Any activity that could disrupt our service (DoS or DDoS).
- Content spoofing and text injection without a demonstrated attack vector.
- Rate limiting or brute force issues.
- Missing best practices in Content Security Policy.
- Missing HttpOnly or Secure flags on cookies.
- Missing email best practices (SPF, DKIM, DMARC).
- Vulnerabilities in third-party services.
- Vulnerabilities affecting only outdated or unpatched browsers.
- Physical testing, social engineering, or other non-technical vulnerabilities.
- Open redirects, unless an additional security impact can be demonstrated.
- Email or username enumeration.
- Tab-nabbing and self-XSS.
- Vulnerabilities related to autofill on web forms.
- Missing security headers that do not lead to direct exploitation.
- Vulnerabilities that apply only to your own account.
Good faith
Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of the platform. Minors are welcome to participate. The Children's Online Privacy Protection Act (COPPA) restricts our ability to collect personal information from children under 13, so participants 12 or younger will need to claim rewards through a parent or legal guardian.
Safe harbor
If a third party initiates legal action against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this program.
Related
For the broader security program, see the Trust Center, Security Policies, and Audit Logs.
