Bug Bounty Program

1. Purpose

MSPbots operates a multi-tenant platform that processes operational and client-related data. The purpose of this Bug Bounty Program is to identify and remediate security vulnerabilities that could impact:

We invite qualified security researchers to responsibly disclose vulnerabilities in accordance with this policy.

2. Authorization & Safe Harbor

Security testing conducted in good faith, within the scope defined below, is considered authorized by MSPbots.

If you:

MSPbots will:

This safe harbor does not apply to actions outside scope, malicious activity, or violations of applicable law.

3. In-Scope Assets

3.1 Applications & Services

The following MSPbots-owned assets are in scope unless otherwise stated:

3.2 Environments

4. In-Scope Vulnerability Classes

The program prioritizes vulnerabilities that could lead to unauthorized data access or cross-tenant impact, including but not limited to:

4.1 Authentication & Authorization
4.2 Multi-Tenant Isolation (High Priority)
4.3 Data Exposure
4.4 Integrations & Agents

Missing request authentication or signing

5. Out-of-Scope

The following activities and findings are not eligible for rewards:

6. Rules of Engagement

Permitted
Prohibited

Researchers must immediately stop testing once unauthorized data access is confirmed.

7. Severity Classification

Severity is determined based on data sensitivity, exploitability, and scope of impact.

Data Classification (used for severity assessment)

Severity
Description
Critical
Cross-tenant access to sensitive tenant data (Integration/customer records, PII, secrets), auth bypass leading to unrestricted data exposure.
High
Unauthorized access to sensitive client data or privileged functionality.
Medium
Limited data exposure or logic flaws with constrained impact.
Low
Minor information disclosure without direct data or security impact.

8. Rewards

Rewards are determined by:

Duplicate reports are rewarded only for the first valid submission.

Severity
Award
Low/Informational
$50
Medium
$100
High
$150
Critical
$200 - $300

9. Reporting Requirements

All submissions must be submitted to support@mspbots.ai and include:

Incomplete reports may be delayed or closed.

10. Response & Disclosure Process

We strongly support coordinated disclosure.

11. Compliance Alignment

This Bug Bounty Program supports MSPbots’ compliance and security posture, including:

12. Policy Updates

MSPbots reserves the right to update this policy at any time. Material changes will be communicated via this page or the designated reporting channel.