Skip to main content
HypeHost - Logo

Bug Bounty Program

Help make our services more secure and earn rewards of up to R$ 8,000 for valid vulnerabilities.

Important: We do not accept automated reports or AI-generated reports. Submissions without human analysis, raw scanner dumps, or generic LLM-written text will be ignored and are not eligible for a reward.

About the Program

Our customers' security is top priority. We run a bug bounty program to encourage security researchers to report vulnerabilities responsibly.

If you discover a vulnerability in our systems, contact us at security@jeskesolutions.net. We investigate every report and reward valid findings based on severity and potential impact.

We work with the security community to keep our infrastructure safe and reliable. Every reported vulnerability is taken seriously and fixed as quickly as possible.

Reward Levels

Critical

R$ 3,000 - R$ 8,000

Vulnerabilities that can fully compromise system security

High

R$ 800 - R$ 2,000

Vulnerabilities that can cause significant damage

Medium

R$ 300 - R$ 800

Vulnerabilities that can cause moderate damage

Low

R$ 50 - R$ 300

Minor vulnerabilities with limited impact

Program Scope

The following systems are included in the bug bounty program. Testing must be performed only on these authorized systems.

  • Main website (hypehost.com.br)
  • Control panel
  • Customer area
  • Customer support systems

Participation Guidelines

Responsibility

Do not damage our systems or customer data during testing. Test in a controlled way and avoid any action that could degrade service or cause data loss.

Legality

Only test systems that are explicitly in scope. Do not access data that does not belong to you and respect other users' privacy.

Confidentiality

Do not publicly disclose vulnerabilities before they are fixed. We credit researchers after the fix if desired.

First Report Wins

Only the first person to report a specific vulnerability will receive the reward. Make sure to provide complete information in the first contact.

Program Exclusions

The following types of issues are not eligible for rewards:

  • Customer servers (VPS, bare metal, colocation, or any contracted service) - not covered by the program and must not be tested
  • Automated reports, bulk scanner dumps without manual analysis, or AI-generated reports
  • UI, CSS, usability, design, spelling, or translation issues
  • DDoS, brute-force, spam, or service overload attempts
  • Vulnerabilities in third-party systems
  • Social engineering or phishing
  • Already known and reported vulnerabilities
  • Informational findings without concrete exploitation (security headers, CORS, cookies, exposed versions, path disclosure, open redirects to trusted domains, or rate-limit bypass without impact)
  • Issues that require deliberate user action (self-XSS, token grabbers, malware requiring manual download/execution, clickjacking without sensitive data, or self-doxxing)
  • Issues in non-public development or staging environments
  • Vulnerabilities in outdated software after notification
  • Network, connectivity, or server configuration issues without demonstrable security impact

How to Report

To report a vulnerability, email security@jeskesolutions.net including the following information:

  • Detailed description of the vulnerability
  • Steps to reproduce the issue
  • Evidence (screenshots, videos, logs)
  • Potential impact of the vulnerability
  • Your contact information and payment details (Pix or crypto wallet)

Found a vulnerability?

Get in touch. We value your help keeping our services secure.

security@jeskesolutions.net

Frequently asked questions (FAQ)

See the most common questions about our Bug Bounty Program.

Talk to us on WhatsApp