Program & scope
The document we triage against.
Read this before you start testing. It defines what is in scope, what is not, how findings are scored, how they are recognised, and the protection you have when you follow it.
Recognition & rewards
What a valid report earns.
Hall of Fame
Public credit for your contribution.
Exclusive swag
Custom Prop Firm Match gear for medium, high and critical submissions.
Monetary rewards
For critical findings — and exceptional high-severity findings, at our discretion.
Reward decisions are final and based on severity, reproducibility, and report quality. Severity is set by the PFM security team using CVSS 3.1 during triage — the score you calculate when submitting is your assessment, not the binding one. Every valid severity — low through critical — counts on the leaderboard. Informative findings earn reputation too, rather than a payout.
Service levels
What we commit to, and by when.
- First response
- Within 2 business days
- Time to triage
- Within 10 business days
- Time to recognition
- Within 14 business days
- Time to resolution
- Varies with complexity and severity
Business days, excluding weekends and public holidays. Every state change is timestamped in the report thread, so you can see where yours sits against these targets.
Scope
What you may test.
In scope
- propfirmmatch.comMain web application
- www.propfirmmatch.comMain web application
- api.propfirmmatch.comPublic API
- *.propfirmmatch.comAny other production subdomain
- propfirmone.comMain web application
- *.propfirmone.comAny other production subdomain
Out of scope
- Issues requiring physical access to a device.
- Issues that only affect outdated or unpatched browsers.
- Cosmetic UI issues, such as misalignments.
- Clickjacking on non-sensitive or static pages.
- Missing security headers with no demonstrated exploitability.
- Vulnerabilities in third-party software we do not control.
- Rate limit or caching glitches, such as view and like counts.
- CSRF without a proven exploit.
- Broken links or redirects with no security impact.
- Unvalidated output from automated tools.
Program rules
What makes a report eligible.
- 01Be the first to report the issue.
- 02Focus on in-scope assets owned by Prop Firm Match.
- 03Never access, modify, or store user data.
- 04No public disclosure before we close the report.
- 05Use automated tools responsibly.
- 06Always comply with applicable laws.
Rules of engagement
Eligibility is above; this is conduct. Research that breaks these is out of the program whether or not the finding is real.
- Use test accounts only.
- Do not exploit vulnerabilities beyond what is necessary to prove impact.
- Avoid denial of service, brute-force, or spam attacks.
- No phishing or social engineering, especially targeting staff.
What we are looking for
Vulnerability classes we accept.
- Broken Access Control / IDOR
- Authentication / Session Management
- Cross-Site Scripting (XSS)
- SQL / NoSQL Injection
- Server-Side Request Forgery (SSRF)
- Cross-Site Request Forgery (CSRF)
- Remote Code Execution (RCE)
- Business Logic Flaw
- Sensitive Data Exposure
- Security Misconfiguration
- Subdomain Takeover
- Race Condition
- Open Redirect
Anything else with a demonstrated, exploitable impact is welcome under “Other”. Impact is what we score — a finding without a working exploit path is informative, not a vulnerability.
Disclosure & legal
What happens after a fix.
Disclosure
- Informative reports are not disclosed.
- With your permission, high-impact discoveries may be featured in community updates or blog posts.
Legal notice
- You must comply with all local, national, and international laws.
- You are responsible for any taxes on rewards you receive.
- Prop Firm Match may modify or terminate this program at any time. Changes do not apply retroactively.
Safe harbour
Your protection under this policy.
Research performed in good faith and in line with these rules is authorized under this policy. PFM will not initiate legal action for accidental, good-faith violations, and will not refer researchers to law enforcement for activity conducted in compliance with this program.
Good faith means staying inside the scope above, following the rules of engagement, and telling us as soon as you realise you have gone further than you intended. If that happens, stop and report it — the protection holds.