Private program · propfirmmatch.com

Know what your finding scores.

We score every report with CVSS 3.1 and triage against the severity it lands in. Set the vector for what you found — this is the same calculation our triage team runs, so the number you see here is the number we work from.

Base score9.8critical

What it earns

  • Hall of fame
  • Swag
  • Discretionary monetary reward

Monetary rewards are for critical reports and are awarded at PFM's discretion. Final severity is set by our team during triage.

AV · Attack Vector

AC · Attack Complexity

PR · Privileges Required

UI · User Interaction

S · Scope

C · Confidentiality

I · Integrity

A · Availability

Your vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Change any metric above to re-score.

Recognition & rewards

Credit first. Swag from medium up. Money for the critical ones.

Severity is set with CVSS 3.1 during triage, so the ranking is the specification’s and not a negotiation. Every valid severity — low included — counts on the leaderboard. What it earns is set out below.

  • Hall of Fame

    Public credit for your contribution.

  • Exclusive swag

    Custom Prop Firm Match gear for medium, high and critical submissions.

  • Monetary rewards

    For critical findings — and exceptional high-severity findings, at our discretion.

Reward decisions are final and based on severity, reproducibility, and report quality. Severity is set by the PFM security team using CVSS 3.1 during triage — the score you calculate when submitting is your assessment, not the binding one. Every valid severity — low through critical — counts on the leaderboard. Informative findings earn reputation too, rather than a payout.

Service levels

You should never have to ask where your report stands.

First response
Within 2 business days
Time to triage
Within 10 business days
Time to recognition
Within 14 business days
Time to resolution
Varies with complexity and severity

Business days, excluding weekends and public holidays. Every state change is timestamped in the report thread, so you can see where yours sits against these targets.

The process

What happens after you press submit.

  1. Step 1 · new

    You file it

    One vulnerability per report, with the steps to reproduce it. The report gets a code and lands in our triage queue immediately.

  2. Step 2 · triaging

    We reproduce it

    We work through your steps and set the CVSS 3.1 severity ourselves. If we cannot reproduce it, we come back to you in the report thread rather than closing it.

  3. Step 3 · accepted

    Accepted

    Confirmed as a real finding against an in-scope asset. From here it is ours to fix, and your place in the hall of fame is secured.

  4. Step 4 · resolved

    Fixed and closed

    The fix is deployed. You are free to disclose publicly once we confirm in the thread — never before.

  5. Step 5 · bounty

    Rewarded

    Credit in the hall of fame, swag from medium severity up, and — for critical findings (plus exceptional highs, at our discretion) — a monetary reward. Every valid severity, low included, moves your reputation on the leaderboard.

Scope

Everything on the production surface, and nothing outside it.

In scope

  • propfirmmatch.comMain web application
  • www.propfirmmatch.comMain web application
  • api.propfirmmatch.comPublic API
  • *.propfirmmatch.comAny other production subdomain
  • propfirmone.comMain web application
  • *.propfirmone.comAny other production subdomain

Out of scope

  • Issues requiring physical access to a device.
  • Issues that only affect outdated or unpatched browsers.
  • Cosmetic UI issues, such as misalignments.
  • Clickjacking on non-sensitive or static pages.
  • Missing security headers with no demonstrated exploitability.
  • Vulnerabilities in third-party software we do not control.
  • Rate limit or caching glitches, such as view and like counts.
  • CSRF without a proven exploit.
  • Broken links or redirects with no security impact.
  • Unvalidated output from automated tools.

Program rules

  1. 01Be the first to report the issue.
  2. 02Focus on in-scope assets owned by Prop Firm Match.
  3. 03Never access, modify, or store user data.
  4. 04No public disclosure before we close the report.
  5. 05Use automated tools responsibly.
  6. 06Always comply with applicable laws.

Safe harbour

Research performed in good faith and in line with these rules is authorized under this policy. PFM will not initiate legal action for accidental, good-faith violations, and will not refer researchers to law enforcement for activity conducted in compliance with this program.


Read the full policy before you start testing — it is the document we triage against.

Program & scope

Bring us something real and we will make it count.

Accounts are free, triage is done by the people who wrote the code, and every report gets a reply in its thread.