Bug Bounty Program
Help make our services more secure and earn rewards of up to R$ 8,000 for valid vulnerabilities.
Important: We do not accept automated reports or AI-generated reports. Submissions without human analysis, raw scanner dumps, or generic LLM-written text will be ignored and are not eligible for a reward.
About the Program
Our customers' security is top priority. We run a bug bounty program to encourage security researchers to report vulnerabilities responsibly.
If you discover a vulnerability in our systems, contact us at security@jeskesolutions.net. We investigate every report and reward valid findings based on severity and potential impact.
We work with the security community to keep our infrastructure safe and reliable. Every reported vulnerability is taken seriously and fixed as quickly as possible.
Reward Levels
Critical
R$ 3,000 - R$ 8,000Vulnerabilities that can fully compromise system security
High
R$ 800 - R$ 2,000Vulnerabilities that can cause significant damage
Medium
R$ 300 - R$ 800Vulnerabilities that can cause moderate damage
Low
R$ 50 - R$ 300Minor vulnerabilities with limited impact
Program Scope
The following systems are included in the bug bounty program. Testing must be performed only on these authorized systems.
- Main website (hypehost.com.br)
- Control panel
- Customer area
- Customer support systems
Participation Guidelines
Responsibility
Do not damage our systems or customer data during testing. Test in a controlled way and avoid any action that could degrade service or cause data loss.
Legality
Only test systems that are explicitly in scope. Do not access data that does not belong to you and respect other users' privacy.
Confidentiality
Do not publicly disclose vulnerabilities before they are fixed. We credit researchers after the fix if desired.
First Report Wins
Only the first person to report a specific vulnerability will receive the reward. Make sure to provide complete information in the first contact.
Program Exclusions
The following types of issues are not eligible for rewards:
- Customer servers (VPS, bare metal, colocation, or any contracted service) - not covered by the program and must not be tested
- Automated reports, bulk scanner dumps without manual analysis, or AI-generated reports
- UI, CSS, usability, design, spelling, or translation issues
- DDoS, brute-force, spam, or service overload attempts
- Vulnerabilities in third-party systems
- Social engineering or phishing
- Already known and reported vulnerabilities
- Informational findings without concrete exploitation (security headers, CORS, cookies, exposed versions, path disclosure, open redirects to trusted domains, or rate-limit bypass without impact)
- Issues that require deliberate user action (self-XSS, token grabbers, malware requiring manual download/execution, clickjacking without sensitive data, or self-doxxing)
- Issues in non-public development or staging environments
- Vulnerabilities in outdated software after notification
- Network, connectivity, or server configuration issues without demonstrable security impact
How to Report
To report a vulnerability, email security@jeskesolutions.net including the following information:
- Detailed description of the vulnerability
- Steps to reproduce the issue
- Evidence (screenshots, videos, logs)
- Potential impact of the vulnerability
- Your contact information and payment details (Pix or crypto wallet)
Found a vulnerability?
Get in touch. We value your help keeping our services secure.
security@jeskesolutions.netFrequently asked questions (FAQ)
See the most common questions about our Bug Bounty Program.