Legal

Researcher Agreement

The permission to test our production systems, the limits of that permission, and the protections that come with it.

Version
1
Effective
2026-09-21

1. What you are authorised to do

Prop Firm Match Global - FZCO authorises you to conduct security testing against the systems listed as in scope in the program policy, for the purpose of finding and reporting vulnerabilities, for as long as this agreement is in force.

This authorisation is the permission required by computer-misuse legislation in many jurisdictions. It is given to you personally and is not transferable.

The systems in scope are Prop Firm Match's own production systems, listed in the program policy. This agreement is what authorises you to test them; the Prop Firm Match Terms of Service, which otherwise prohibit unauthorised access to https://propfirmmatch.com, are disapplied to the extent of the permission given here and only to that extent.

It covers the in-scope systems only. Anything not listed as in scope is not authorised, including systems belonging to our customers, our vendors, or third parties whose services appear on our surface.

The scope is written as wildcards with named exceptions, and the exceptions are part of the grant rather than a footnote to it. A host listed as out of scope is NOT authorised even though a wildcard above it appears to cover it — at the date of this version those are spreads.propfirmmatch.com, security.propfirmmatch.com and training.propfirmmatch.com. Read the program policy for the current list before you begin; it is the operative one.

security.propfirmmatch.com is this platform, and it is outside its own program. If you find something here, tell us at the security address — we want to know — but it earns no reward and this authorisation does not cover testing it.

Authorisation applies from the moment you accept this agreement and ends when you stop participating, when we withdraw it, or when the program ends.

2. The limits of that permission

Access only the data you need to demonstrate an issue. Stop as soon as you have demonstrated it.

Do not access, modify, delete or exfiltrate other people's data. If you encounter personal data, stop, do not retain a copy, and tell us in the report.

Do not degrade a service for anyone else: no denial of service, no load testing, no spam, no mass automated scanning that affects availability.

Do not use social engineering, phishing, or physical intrusion against our staff, our customers, or our suppliers.

Do not pivot from an in-scope system into anything out of scope, even when it is technically reachable.

Testing outside these limits is outside your authorisation, and the safe harbour in section 4 does not cover it.

3. Reporting and confidentiality

Report through this platform, promptly, with enough detail for us to reproduce the issue.

Keep the finding confidential until we confirm it is resolved, or until 90 days after you reported it, whichever comes first. If we need longer, we will ask you and explain why; we will not refuse unreasonably.

Do not publish or share details, including proof-of-concept code, with anyone else during that period.

You may always tell your national CERT or equivalent authority, and nothing here prevents you from making a protected disclosure or reporting a crime.

4. Safe harbour

Where you act in good faith and within this agreement and the program policy, we will treat your research as authorised conduct. Specifically:

We will not bring or support a civil claim against you arising from that research.

We will not report you to law enforcement for that research.

Where a third party or a public authority contacts us about your activity, we will, acting reasonably and without undue delay, confirm to them in writing that the research was authorised under this program. We will do this on our own initiative where we are able to, and in any event on your request.

Where a third party brings or threatens a claim against you arising from conduct we authorised here, we will not assist that claim, and we will provide you with a written confirmation of your authorisation that you may produce to them or to a court.

What we cannot do is control the third party. This is an undertaking to state the truth about what we authorised, clearly and in writing; it is not an indemnity and it is not a promise about the outcome.

If we conclude that something you did fell outside this agreement, we will tell you and give you a reasonable opportunity to explain before we take any step against you, unless the law requires us to act immediately or the conduct is plainly malicious.

A good-faith mistake — reaching something you should not have, misjudging scope — is not a breach of this agreement, provided you stop, tell us, and do not retain what you found.

This safe harbour is given by us and binds us. It cannot bind anyone else, and it does not authorise you to break the law.

5. Recognition and rewards

Valid findings earn recognition under the program policy. Monetary rewards are discretionary and conditional, and section 4 of the Terms of Service sets out the eligibility, sanctions screening and documentation requirements that apply before we can pay.

Where you disagree with an assessment, the dispute process in section 5 of the Terms of Service applies. Start it by replying on the report thread or writing to security@propfirmmatch.com.

You are not our employee, contractor, agent or partner, and this agreement does not create any of those relationships. Nothing here obliges us to pay for a report, and nothing here obliges you to look for one.

6. Data you encounter

If your testing exposes personal data belonging to someone else, you are handling that data only to demonstrate the issue to us. Delete any copy once the report is filed, and confirm in the thread that you have.

We may be required to notify a regulator or affected individuals about an incident your report reveals. Where we do, we will not name you unless you agree or the law requires it.

7. Duration, changes and law

This agreement starts when you accept it and continues until you or we end it. You may end it at any time by telling us or by closing your account. We may end it at any time, on notice.

Sections 3, 4 and 6 survive the end of this agreement in respect of research you carried out while it was in force.

Each version of this agreement carries a number and an effective date. A change applies from its effective date only: research you already did is judged under the version in force when you did it. We will ask you to accept a new version before you continue.

This agreement is governed by the laws of Dubai, United Arab Emirates, and the courts of the courts of Dubai, United Arab Emirates have jurisdiction, on the same terms as section 9 of the Terms of Service.