Program & scope

The document we triage against.

Read this before you start testing. It defines what is in scope, what is not, how findings are scored, how they are recognised, and the protection you have when you follow it.

Recognition & rewards

What a valid report earns.

  • Hall of Fame

    Public credit for your contribution.

  • Exclusive swag

    Custom Prop Firm Match gear for medium, high and critical submissions.

  • Monetary rewards

    For critical findings — and exceptional high-severity findings, at our discretion.

Reward decisions are final and based on severity, reproducibility, and report quality. Severity is set by the PFM security team using CVSS 3.1 during triage — the score you calculate when submitting is your assessment, not the binding one. Every valid severity — low through critical — counts on the leaderboard. Informative findings earn reputation too, rather than a payout.

Service levels

What we commit to, and by when.

First response
Within 2 business days
Time to triage
Within 10 business days
Time to recognition
Within 14 business days
Time to resolution
Varies with complexity and severity

Business days, excluding weekends and public holidays. Every state change is timestamped in the report thread, so you can see where yours sits against these targets.

Scope

What you may test.

In scope

  • propfirmmatch.comMain web application
  • www.propfirmmatch.comMain web application
  • api.propfirmmatch.comPublic API
  • *.propfirmmatch.comAny other production subdomain
  • propfirmone.comMain web application
  • *.propfirmone.comAny other production subdomain

Out of scope

  • Issues requiring physical access to a device.
  • Issues that only affect outdated or unpatched browsers.
  • Cosmetic UI issues, such as misalignments.
  • Clickjacking on non-sensitive or static pages.
  • Missing security headers with no demonstrated exploitability.
  • Vulnerabilities in third-party software we do not control.
  • Rate limit or caching glitches, such as view and like counts.
  • CSRF without a proven exploit.
  • Broken links or redirects with no security impact.
  • Unvalidated output from automated tools.

Program rules

What makes a report eligible.

  1. 01Be the first to report the issue.
  2. 02Focus on in-scope assets owned by Prop Firm Match.
  3. 03Never access, modify, or store user data.
  4. 04No public disclosure before we close the report.
  5. 05Use automated tools responsibly.
  6. 06Always comply with applicable laws.

Rules of engagement

Eligibility is above; this is conduct. Research that breaks these is out of the program whether or not the finding is real.

  • Use test accounts only.
  • Do not exploit vulnerabilities beyond what is necessary to prove impact.
  • Avoid denial of service, brute-force, or spam attacks.
  • No phishing or social engineering, especially targeting staff.

What we are looking for

Vulnerability classes we accept.

  • Broken Access Control / IDOR
  • Authentication / Session Management
  • Cross-Site Scripting (XSS)
  • SQL / NoSQL Injection
  • Server-Side Request Forgery (SSRF)
  • Cross-Site Request Forgery (CSRF)
  • Remote Code Execution (RCE)
  • Business Logic Flaw
  • Sensitive Data Exposure
  • Security Misconfiguration
  • Subdomain Takeover
  • Race Condition
  • Open Redirect

Anything else with a demonstrated, exploitable impact is welcome under “Other”. Impact is what we score — a finding without a working exploit path is informative, not a vulnerability.

Disclosure & legal

What happens after a fix.

Disclosure

  • Informative reports are not disclosed.
  • With your permission, high-impact discoveries may be featured in community updates or blog posts.

Legal notice

  • You must comply with all local, national, and international laws.
  • You are responsible for any taxes on rewards you receive.
  • Prop Firm Match may modify or terminate this program at any time. Changes do not apply retroactively.

Safe harbour

Your protection under this policy.

Research performed in good faith and in line with these rules is authorized under this policy. PFM will not initiate legal action for accidental, good-faith violations, and will not refer researchers to law enforcement for activity conducted in compliance with this program.


Good faith means staying inside the scope above, following the rules of engagement, and telling us as soon as you realise you have gone further than you intended. If that happens, stop and report it — the protection holds.