Private program · propfirmmatch.com
Know what your finding scores.
We score every report with CVSS 3.1 and triage against the severity it lands in. Set the vector for what you found — this is the same calculation our triage team runs, so the number you see here is the number we work from.
What it earns
- Hall of fame
- Swag
- Discretionary monetary reward
Monetary rewards are for critical reports and are awarded at PFM's discretion. Final severity is set by our team during triage.
AV · Attack Vector
AC · Attack Complexity
PR · Privileges Required
UI · User Interaction
S · Scope
C · Confidentiality
I · Integrity
A · Availability
Your vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Change any metric above to re-score.
Recognition & rewards
Credit first. Swag from medium up. Money for the critical ones.
Severity is set with CVSS 3.1 during triage, so the ranking is the specification’s and not a negotiation. Every valid severity — low included — counts on the leaderboard. What it earns is set out below.
Hall of Fame
Public credit for your contribution.
Exclusive swag
Custom Prop Firm Match gear for medium, high and critical submissions.
Monetary rewards
For critical findings — and exceptional high-severity findings, at our discretion.
Reward decisions are final and based on severity, reproducibility, and report quality. Severity is set by the PFM security team using CVSS 3.1 during triage — the score you calculate when submitting is your assessment, not the binding one. Every valid severity — low through critical — counts on the leaderboard. Informative findings earn reputation too, rather than a payout.
Service levels
You should never have to ask where your report stands.
- First response
- Within 2 business days
- Time to triage
- Within 10 business days
- Time to recognition
- Within 14 business days
- Time to resolution
- Varies with complexity and severity
Business days, excluding weekends and public holidays. Every state change is timestamped in the report thread, so you can see where yours sits against these targets.
The process
What happens after you press submit.
Step 1 · new
You file it
One vulnerability per report, with the steps to reproduce it. The report gets a code and lands in our triage queue immediately.
Step 2 · triaging
We reproduce it
We work through your steps and set the CVSS 3.1 severity ourselves. If we cannot reproduce it, we come back to you in the report thread rather than closing it.
Step 3 · accepted
Accepted
Confirmed as a real finding against an in-scope asset. From here it is ours to fix, and your place in the hall of fame is secured.
Step 4 · resolved
Fixed and closed
The fix is deployed. You are free to disclose publicly once we confirm in the thread — never before.
Step 5 · bounty
Rewarded
Credit in the hall of fame, swag from medium severity up, and — for critical findings (plus exceptional highs, at our discretion) — a monetary reward. Every valid severity, low included, moves your reputation on the leaderboard.
Scope
Everything on the production surface, and nothing outside it.
In scope
- propfirmmatch.comMain web application
- www.propfirmmatch.comMain web application
- api.propfirmmatch.comPublic API
- *.propfirmmatch.comAny other production subdomain
- propfirmone.comMain web application
- *.propfirmone.comAny other production subdomain
Out of scope
- Issues requiring physical access to a device.
- Issues that only affect outdated or unpatched browsers.
- Cosmetic UI issues, such as misalignments.
- Clickjacking on non-sensitive or static pages.
- Missing security headers with no demonstrated exploitability.
- Vulnerabilities in third-party software we do not control.
- Rate limit or caching glitches, such as view and like counts.
- CSRF without a proven exploit.
- Broken links or redirects with no security impact.
- Unvalidated output from automated tools.
Program rules
- 01Be the first to report the issue.
- 02Focus on in-scope assets owned by Prop Firm Match.
- 03Never access, modify, or store user data.
- 04No public disclosure before we close the report.
- 05Use automated tools responsibly.
- 06Always comply with applicable laws.
Safe harbour
Research performed in good faith and in line with these rules is authorized under this policy. PFM will not initiate legal action for accidental, good-faith violations, and will not refer researchers to law enforcement for activity conducted in compliance with this program.
Read the full policy before you start testing — it is the document we triage against.
Program & scopeBring us something real and we will make it count.
Accounts are free, triage is done by the people who wrote the code, and every report gets a reply in its thread.