00 · BUG BOUNTYBreak Bayria.
Break Bayria.
Get paid.
$10k – $50k for criticals. We pay within 14 days of fix.
01 · PAYOUTS
By severity.
● CRITICAL$10,000 – $50,000
Examples: RCE on production · key extraction · arbitrary read on Vault ciphertext
● HIGH$2,500 – $10,000
Examples: Auth bypass · privilege escalation · tunnel leak across customers
● MEDIUM$500 – $2,500
Examples: CSRF on customer panel · stored XSS · IDOR exposing other users' metadata
● LOW$100 – $500
Examples: Open redirect · self-XSS · rate-limit bypass on non-sensitive endpoint
02 · RULES
Six things.
01Email security@bayria.com first, public disclosure only after a fix ships.
02No automated scanners against production — use a staging-eligible account (we'll comp you one).
03Don't pivot once inside. Stop, document, report.
04Don't access another customer's data even briefly. The bounty is in the demo, not the dwell time.
05Social engineering of Bayria staff is out of scope (separate program).
06We pay in USD via Stripe, BTC, or XMR — your choice.
● REPORTEmail security@bayria.com (PGP: 0xDEAD...BEEF) with a clear repro and impact statement. Median triage time: 6 hours.