HypeHost - Logo

Bug Bounty Program

Help make our services more secure and earn rewards of up to R$ 8,000 for valid vulnerabilities.

About the Program

Our customers' security is top priority. We run a bug bounty program to encourage security researchers to report vulnerabilities responsibly.

If you discover a vulnerability in our systems, contact us at security@jeskesolutions.net. We investigate every report and reward valid findings based on severity and potential impact.

We work with the security community to keep our infrastructure safe and reliable. Every reported vulnerability is taken seriously and fixed as quickly as possible.

Reward Levels

Critical

R$ 3,000 - R$ 8,000

Vulnerabilities that can fully compromise system security

High

R$ 800 - R$ 2,000

Vulnerabilities that can cause significant damage

Medium

R$ 300 - R$ 800

Vulnerabilities that can cause moderate damage

Low

R$ 50 - R$ 300

Minor vulnerabilities with limited impact

Program Scope

The following systems are included in the bug bounty program. Testing must be performed only on these authorized systems.

  • Main website (hypehost.com.br)
  • Control panel and customer area
  • Hosting infrastructure
  • Payment and billing systems
  • APIs and integrations
  • Customer support systems

Participation Guidelines

Responsibility

Do not damage our systems or customer data during testing. Test in a controlled way and avoid any action that could degrade service or cause data loss.

Legality

Only test systems that are explicitly in scope. Do not access data that does not belong to you and respect other users' privacy.

Confidentiality

Do not publicly disclose vulnerabilities before they are fixed. We credit researchers after the fix if desired.

First Report Wins

Only the first person to report a specific vulnerability will receive the reward. Make sure to provide complete information in the first contact.

Program Exclusions

The following types of issues are not eligible for rewards:

  • CSS errors and UI issues
  • DDoS attacks and overload attempts
  • Vulnerabilities in third-party systems
  • Usability or design issues
  • Web server misconfigurations
  • Network or connectivity issues
  • Already known and reported vulnerabilities
  • Social engineering or phishing
  • Brute-force attacks
  • Spam or mass email sending
  • Token grabbers that require manual user action
  • Malware that requires user download and execution
  • Clickjacking on pages without sensitive data
  • Self-doxxing or voluntary information disclosure
  • Vulnerabilities in outdated software after notification
  • Rate-limit bypass without demonstrable impact
  • Issues in non-public development or staging environments
  • Spelling issues or translation errors
  • Missing security headers without concrete exploitation
  • Misconfigured CORS without demonstrated exploitation
  • Cookies without the secure flag on non-HTTPS connections
  • Exposed software versions without an associated vulnerability
  • Internal path disclosure without exploitation
  • Open redirects to trusted domains
  • Self-XSS that requires deliberate victim action

How to Report

To report a vulnerability, email security@jeskesolutions.net including the following information:

  • Detailed description of the vulnerability
  • Steps to reproduce the issue
  • Evidence (screenshots, videos, logs)
  • Potential impact of the vulnerability
  • Your contact information and payment details (Pix or crypto wallet)

Found a vulnerability?

Get in touch. We value your help keeping our services secure.

security@jeskesolutions.net

Frequently asked questions (FAQ)

See the most common questions about our Bug Bounty Program.

Talk to us on WhatsApp