Access Public
Bounty Paused
Bounties Paid 3 (avg: $33)

Program Description & Scope

Welcome!

We're excited to invite security bug hunters from all backgrounds to help us make Acquire a more secure platform for everyone. Your expertise helps us identify vulnerabilities before they can be exploited, and we value your contributions to our security efforts.

Program scope

We appreciate reports that can help us improve our security posture. Please review the following details carefully before submitting your findings.

In-scope assets

  • Websites: acquireglobal.com, acquire.co.nz, and acquireit.com.au.
  • API: api.acquireglobal.com.

Out-of-scope assets

  • Any services hosted by third parties, unless they impact the security of our primary assets.
  • Marketing pages (e.g., blog, landing pages).
  • Physical offices and infrastructure.
  • Employee social media accounts.

Vulnerabilities we're interested in

  • Cross-Site Scripting (XSS)
  • SQL Injection
  • Authentication bypass
  • Privilege escalation
  • Misconfigured access controls
  • Remote Code Execution (RCE)
  • Security misconfigurations
  • Server-side request forgery (SSRF)

Vulnerabilities out-of-scope

  • Issues solely affecting outdated browsers.
  • Missing HTTP security headers (unless they lead to a proven vulnerability).
  • Vulnerabilities requiring physical access.
  • Self-XSS requiring significant user interaction.
  • Reports from automated tools without clear evidence of impact.
  • Theoretical vulnerabilities without proof of exploitation.
  • Vulnerabilities already known to us.

Rewards

We offer bounties based on the severity and impact of the vulnerability. As a small business, we evaluate rewards on a case-by-case basis. The examples below are indicative only and do not guarantee a specific payout. Final reward decisions may take into account the affected asset, the sensitivity of the data or function involved, the ease of exploitation, the quality of the reproduction steps, and whether the issue is novel or a duplicate.

  • Critical: Vulnerabilities that could result in full system compromise, remote code execution, significant unauthorised access, or large-scale exposure of sensitive data.
    Examples: remote code execution, authentication bypass leading to administrative access, or database access exposing sensitive customer data.
  • High: Vulnerabilities that allow unauthorised access to sensitive information, significant privilege escalation, or meaningful impact to security controls without full system compromise.
    Examples: privilege escalation, broken access control exposing sensitive records, or account takeover.
  • Medium: Vulnerabilities with demonstrated security impact that may require some user interaction, limited conditions, or affect a smaller set of users or data.
    Examples: cross-site scripting with demonstrated impact, CSRF affecting important actions, or API issues with limited but real exposure.
  • Low: Vulnerabilities with limited security impact, low exploitability, or primarily defensive hardening value.
    Examples: minor information disclosure, weak security configuration with limited practical impact, or low-risk misconfigurations.

Note: Reports without a clear, demonstrated security impact, or those requiring unrealistic attack scenarios, are unlikely to be eligible for a reward.

Submission guidelines

  • Provide clear, step-by-step instructions to reproduce the vulnerability.
  • Include screenshots, videos, or code snippets where possible.
  • Test only on your own accounts; do not access others' data.
  • Describe the potential impact and attack scenario.
  • Be respectful of our users' privacy and our systems' stability.
  • Please submit vulnerability reports through our Bug Bounty Programme. To help us assess your submission quickly, please include a clear description of the issue, the affected asset, endpoint, or URL, step-by-step instructions to reproduce the issue, the potential impact, and any supporting evidence such as screenshots, videos, HTTP requests, or proof-of-concept code.
  • Rewards are generally offered for the first valid, original report of a vulnerability. Duplicate reports or issues already known to us may not be eligible for a bounty.
  • Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate it. If you are unsure whether an issue is in scope, you are welcome to contact us before testing further.

Rate limits & testing constraints

  • Limit requests to no more than 10 requests per minute.
  • Avoid testing that triggers excessive emails or notifications (max 5 per hour).
  • Limit login/authentication attempts to 10 per hour.
  • Avoid any testing that could impact system availability or other users.
  • The following activities are prohibited: denial-of-service testing, spam or notification flooding, phishing or social engineering, physical attacks, malware deployment, and accessing or modifying data belonging to other users except as strictly necessary to demonstrate impact.

Our commitment

  • We aim to acknowledge your report within 7 business days.
  • We aim to provide a resolution or update within 14 business days.
  • We aim to keep you informed about the status of your report.
  • We aim to recognize your contribution if you wish to be acknowledged.

Legal safe harbour

We authorise good-faith security research conducted in a manner consistent with this policy. If you act in good faith, avoid privacy violations, service disruption, and data destruction, and promptly report any vulnerability you discover, we will not initiate legal action against you for accidental, good-faith violations of this policy.

Policy updates

This policy may be updated over time. The latest version will always be available on this page.

Rewards

Bounties are currently paused for this Program