Bug bounty program
Find a vulnerability in the eCourtDate platform, report it through the Security Researcher Portal, and get paid by severity. Every report is validated within 3 business days and every validated report is fixed within 10.
- to confirm and validate a report
- 3business days
- to resolve a validated report
- 10business days
- top reward for a critical finding
- $10,000+
- from $50 to $10,000+ by CVSS severity
- 6reward tiers
From report to reward
A defined lifecycle with dates attached. Researchers know what happens next at every step, and the platform gets fixed faster.
- 1
Register in the portal
Every researcher registers in the Security Researcher Portal before testing. Professional researchers can request a free researcher account there, so testing never touches production data.
- 2
Research within scope
Test the *.ecourtdate.com platform in good faith, and stay clear of the safety and privacy of the people the platform serves.
- 3
Submit the report in the portal
Include a clear description, reproduction steps, and a proof of concept. Reports are accepted only through the portal, and the more precise the report, the faster it validates.
- 4
Validation within 3 business days
The security team confirms receipt, reproduces the issue, and assigns a CVSS severity rating. You hear back within 3 business days either way.
- 5
Resolution within 10 business days
Validated reports are fixed within 10 business days. You can track status in the portal, and the team will follow up if more detail is needed to verify the fix.
- 6
Reward paid by severity
Once the report is validated, the reward for its CVSS rating is paid. Compensation is not tied to when the fix ships, and it is conditional on keeping the finding and eCourtDate’s name confidential.
Rewards by severity
Compensation is based on the CVSS severity rating of a validated report. Every severity tier is paid, including informational findings, when the report meets the program terms.
Critical
CVSS 9.0 to 10.0$10,000+
per validated report
High
CVSS 7.0 to 8.9$5,000
per validated report
Medium
CVSS 4.0 to 6.9$2,500
per validated report
Low
CVSS 1.1 to 3.9$500
per validated report
Very low
CVSS 0.1 to 1.0$100
per validated report
Informational / usability
CVSS 0$50
per validated report
The first valid report of an issue receives the reward. Reports that share a root cause are treated as one finding. Rewards are paid in U.S. dollars once the report is validated. To qualify, the researcher must not publicly disclose the vulnerability or identify eCourtDate as the affected company without written permission from the security team.
What is in scope
The program covers technical vulnerabilities in the *.ecourtdate.com platform: the web applications, APIs, and services that courts and justice agencies use to run communications, scheduling, payments, and case operations.
The platform runs in AWS GovCloud and handles data for 10,000+ courts and justice locations. Please do not attempt to compromise the safety or privacy of the people it serves. A free researcher account gives you a place to test without touching production data.
Testing accounts
Professional security researchers receive a free researcher account for testing. Request one in the portal with a link to your professional profile (LinkedIn, GitHub, Bugcrowd, HackerOne, or similar). Accounts are not provided for anonymous requests.
- Test against your own account and data, never a customer agency’s.
- Findings that apply only to your own account are out of scope.
What is out of scope
Check a finding against this list before submitting. Most are excluded because they carry no demonstrated impact on their own; several become eligible once a real attack is shown.
Low impact without a demonstrated attack
- Clickjacking on pages with no sensitive actions.
- Cross-site request forgery (CSRF) on unauthenticated forms or forms with no sensitive actions.
- Content spoofing and text injection without a demonstrated attack vector.
- Open redirects, unless an additional security impact can be demonstrated.
- Tab-nabbing and self-XSS.
- Email or username enumeration.
- Rate limiting or brute force issues.
- Vulnerabilities related to autofill on web forms.
Configuration and best-practice gaps
- Missing security headers that do not lead to direct exploitation.
- Missing best practices in Content Security Policy.
- Missing best practices in SSL/TLS configuration.
- Missing HttpOnly or Secure flags on cookies.
- Missing email best practices (SPF, DKIM, DMARC).
Needs a working proof of concept
- Previously known vulnerable libraries without a working proof of concept.
- CSV injection without demonstrating a vulnerability.
- Vulnerabilities that apply only to your own account.
Outside the program entirely
- Any activity that could disrupt our service (DoS or DDoS).
- Vulnerabilities in third-party services.
- Vulnerabilities affecting only outdated or unpatched browsers.
- Attacks requiring man-in-the-middle or physical access to a user’s device.
- Physical testing, social engineering, or other non-technical vulnerabilities.
What a strong report includes
Validation is fastest when the team can reproduce the issue on the first attempt. Include as much of this as you can.
- 1
A clear description
What the vulnerability is, where it lives (URL, endpoint, or feature), and what an attacker could do with it.
- 2
Reproduction steps
The exact sequence to trigger the issue, including any account role, request payload, or configuration required.
- 3
A proof of concept
A request, script, or screen recording that demonstrates the impact. Reports with a working proof of concept validate fastest.
- 4
Your severity assessment
A proposed CVSS vector helps the team confirm the rating quickly. The final rating is assigned during validation.
Research in good faith
Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of the platform. These four rules keep research safe for the agencies and people who depend on it.
Protect privacy
Do not access, modify, or retain data that is not your own. If you encounter personal information, stop, record only what is needed to report the issue, and tell us.
Leave data intact
Avoid destruction of data and any change to records the platform holds. Use test data in your own researcher account wherever possible.
Keep the service running
Avoid interruption or degradation of the platform. Courts and justice agencies rely on it every day, and disruptive testing is out of scope.
Respect the people served
The platform reaches people with court dates, payments, and supervision obligations. Do not attempt to compromise their safety or privacy.
Minors are welcome to participate. The Children’s Online Privacy Protection Act (COPPA) restricts our ability to collect personal information from children under 13, so participants 12 or younger claim rewards through a parent or legal guardian.
Safe harbor
If a third party initiates legal action against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this program.
Research that stays within scope, follows the good faith rules, and is reported through the channels on this page is authorized research under this policy.
Non-disclosure
To qualify for a reward, do not publish the vulnerability or identify eCourtDate as the affected company, before or after the fix, without written permission from the security team. Agencies on the platform stay protected, and the reward stays yours.
Bug bounty FAQ
The questions researchers ask most before submitting.
How do researchers submit a report?
How quickly does eCourtDate respond?
How is the reward amount decided?
What happens if the same issue has already been reported?
Is a test account available?
What is in scope?
Does the program accept reports from customers?
Can findings be published?
Can minors participate?
Is research under this policy protected?
Start with the Security Researcher Portal
Every report starts here. Register once, submit findings, track validation and payout status, and request a researcher account for testing.
Policy last updated August 2026. All reports go through the Security Researcher Portal. Machine-readable policy pointer at /.well-known/security.txt. For the broader security program, see the Trust Center, Security Policies, and Audit Logs.
