Bug bounty program

Find a vulnerability in the eCourtDate platform, report it through the Security Researcher Portal, and get paid by severity. Every report is validated within 3 business days and every validated report is fixed within 10.

to confirm and validate a report
3business days
to resolve a validated report
10business days
top reward for a critical finding
$10,000+
from $50 to $10,000+ by CVSS severity
6reward tiers

From report to reward

A defined lifecycle with dates attached. Researchers know what happens next at every step, and the platform gets fixed faster.

  1. 1

    Register in the portal

    Every researcher registers in the Security Researcher Portal before testing. Professional researchers can request a free researcher account there, so testing never touches production data.

  2. 2

    Research within scope

    Test the *.ecourtdate.com platform in good faith, and stay clear of the safety and privacy of the people the platform serves.

  3. 3

    Submit the report in the portal

    Include a clear description, reproduction steps, and a proof of concept. Reports are accepted only through the portal, and the more precise the report, the faster it validates.

  4. 4

    Validation within 3 business days

    The security team confirms receipt, reproduces the issue, and assigns a CVSS severity rating. You hear back within 3 business days either way.

  5. 5

    Resolution within 10 business days

    Validated reports are fixed within 10 business days. You can track status in the portal, and the team will follow up if more detail is needed to verify the fix.

  6. 6

    Reward paid by severity

    Once the report is validated, the reward for its CVSS rating is paid. Compensation is not tied to when the fix ships, and it is conditional on keeping the finding and eCourtDate’s name confidential.

Rewards by severity

Compensation is based on the CVSS severity rating of a validated report. Every severity tier is paid, including informational findings, when the report meets the program terms.

  • Critical

    CVSS 9.0 to 10.0

    $10,000+

    per validated report

  • High

    CVSS 7.0 to 8.9

    $5,000

    per validated report

  • Medium

    CVSS 4.0 to 6.9

    $2,500

    per validated report

  • Low

    CVSS 1.1 to 3.9

    $500

    per validated report

  • Very low

    CVSS 0.1 to 1.0

    $100

    per validated report

  • Informational / usability

    CVSS 0

    $50

    per validated report

The first valid report of an issue receives the reward. Reports that share a root cause are treated as one finding. Rewards are paid in U.S. dollars once the report is validated. To qualify, the researcher must not publicly disclose the vulnerability or identify eCourtDate as the affected company without written permission from the security team.

What is in scope

The program covers technical vulnerabilities in the *.ecourtdate.com platform: the web applications, APIs, and services that courts and justice agencies use to run communications, scheduling, payments, and case operations.

The platform runs in AWS GovCloud and handles data for 10,000+ courts and justice locations. Please do not attempt to compromise the safety or privacy of the people it serves. A free researcher account gives you a place to test without touching production data.

Testing accounts

Professional security researchers receive a free researcher account for testing. Request one in the portal with a link to your professional profile (LinkedIn, GitHub, Bugcrowd, HackerOne, or similar). Accounts are not provided for anonymous requests.

  • Test against your own account and data, never a customer agency’s.
  • Findings that apply only to your own account are out of scope.

What is out of scope

Check a finding against this list before submitting. Most are excluded because they carry no demonstrated impact on their own; several become eligible once a real attack is shown.

Low impact without a demonstrated attack

  • Clickjacking on pages with no sensitive actions.
  • Cross-site request forgery (CSRF) on unauthenticated forms or forms with no sensitive actions.
  • Content spoofing and text injection without a demonstrated attack vector.
  • Open redirects, unless an additional security impact can be demonstrated.
  • Tab-nabbing and self-XSS.
  • Email or username enumeration.
  • Rate limiting or brute force issues.
  • Vulnerabilities related to autofill on web forms.

Configuration and best-practice gaps

  • Missing security headers that do not lead to direct exploitation.
  • Missing best practices in Content Security Policy.
  • Missing best practices in SSL/TLS configuration.
  • Missing HttpOnly or Secure flags on cookies.
  • Missing email best practices (SPF, DKIM, DMARC).

Needs a working proof of concept

  • Previously known vulnerable libraries without a working proof of concept.
  • CSV injection without demonstrating a vulnerability.
  • Vulnerabilities that apply only to your own account.

Outside the program entirely

  • Any activity that could disrupt our service (DoS or DDoS).
  • Vulnerabilities in third-party services.
  • Vulnerabilities affecting only outdated or unpatched browsers.
  • Attacks requiring man-in-the-middle or physical access to a user’s device.
  • Physical testing, social engineering, or other non-technical vulnerabilities.

What a strong report includes

Validation is fastest when the team can reproduce the issue on the first attempt. Include as much of this as you can.

  1. 1

    A clear description

    What the vulnerability is, where it lives (URL, endpoint, or feature), and what an attacker could do with it.

  2. 2

    Reproduction steps

    The exact sequence to trigger the issue, including any account role, request payload, or configuration required.

  3. 3

    A proof of concept

    A request, script, or screen recording that demonstrates the impact. Reports with a working proof of concept validate fastest.

  4. 4

    Your severity assessment

    A proposed CVSS vector helps the team confirm the rating quickly. The final rating is assigned during validation.

Research in good faith

Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of the platform. These four rules keep research safe for the agencies and people who depend on it.

Protect privacy

Do not access, modify, or retain data that is not your own. If you encounter personal information, stop, record only what is needed to report the issue, and tell us.

Leave data intact

Avoid destruction of data and any change to records the platform holds. Use test data in your own researcher account wherever possible.

Keep the service running

Avoid interruption or degradation of the platform. Courts and justice agencies rely on it every day, and disruptive testing is out of scope.

Respect the people served

The platform reaches people with court dates, payments, and supervision obligations. Do not attempt to compromise their safety or privacy.

Minors are welcome to participate. The Children’s Online Privacy Protection Act (COPPA) restricts our ability to collect personal information from children under 13, so participants 12 or younger claim rewards through a parent or legal guardian.

Safe harbor

If a third party initiates legal action against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this program.

Research that stays within scope, follows the good faith rules, and is reported through the channels on this page is authorized research under this policy.

Non-disclosure

To qualify for a reward, do not publish the vulnerability or identify eCourtDate as the affected company, before or after the fix, without written permission from the security team. Agencies on the platform stay protected, and the reward stays yours.

Bug bounty FAQ

The questions researchers ask most before submitting.

How do researchers submit a report?
Register in the Security Researcher Portal at research.ecourtdate.net and submit the report there. Include a clear description, reproduction steps, and a proof of concept. Reports sent by email or other channels are redirected to the portal. The machine-readable pointer to this policy is published at /.well-known/security.txt per RFC 9116.
How quickly does eCourtDate respond?
Reports are confirmed and validated within 3 business days. Validated reports are resolved within 10 business days. Status is visible in the portal throughout.
How is the reward amount decided?
Rewards are set by the CVSS severity rating assigned to the validated report: $50 for informational or usability findings, $100 for very low, $500 for low, $2,500 for medium, $5,000 for high, and $10,000 or more for critical.
What happens if the same issue has already been reported?
The first valid report of an issue receives the reward. Later reports of the same root cause are treated as duplicates and are not eligible for a separate payout, but the team will confirm the duplicate status so you know where you stand.
Is a test account available?
Yes. Professional security researchers receive a free researcher account for testing. Request one in the portal with a link to a professional profile such as LinkedIn, GitHub, Bugcrowd, or HackerOne. Accounts are not provided for anonymous requests.
What is in scope?
Technical vulnerabilities in the *.ecourtdate.com platform. Third-party services and the other exclusions listed on this page are out of scope.
Does the program accept reports from customers?
Yes. The program is open to anyone who finds a vulnerability in good faith, including agency staff and IT teams at customer agencies. The same response times and rewards apply.
Can findings be published?
Not without written permission from the security team. To qualify for a reward, researchers agree not to publicly disclose the vulnerability or identify eCourtDate as the affected company, before or after the fix. Public disclosure without permission forfeits the reward.
Can minors participate?
Yes. The Children’s Online Privacy Protection Act (COPPA) restricts our ability to collect personal information from children under 13, so participants 12 or younger claim rewards through a parent or legal guardian.
Is research under this policy protected?
If a third party initiates legal action against you and you have complied with this policy, eCourtDate will take steps to make it known that your actions were conducted in compliance with this program.

Start with the Security Researcher Portal

Every report starts here. Register once, submit findings, track validation and payout status, and request a researcher account for testing.

Policy last updated August 2026. All reports go through the Security Researcher Portal. Machine-readable policy pointer at /.well-known/security.txt. For the broader security program, see the Trust Center, Security Policies, and Audit Logs.