Security

Bug Bounty Program

We take security seriously. If you discover a vulnerability in KumoBuilder, we want to hear from you — and we reward responsible disclosure.

Reward tiers

Critical
RCE, auth bypass, mass data exfiltration, cross-tenant data access
$500–$2,000
High
Privilege escalation, significant PII leak, stored XSS
$200–$500
Normal
CSRF, reflected XSS, sensitive data in logs, insecure direct object reference
$50–$200
Low
Minor information disclosure, UI redressing, low-impact misconfigurations
Acknowledgement

In scope

kumobuilder.com and all subdomains
API endpoints (api.kumobuilder.com)
Authentication & session management
Multi-tenant data isolation
AI pipeline endpoints
Website generation endpoints
Admin panel (admin.kumobuilder.com)

Out of scope

Third-party services and dependencies
DoS / DDoS attacks
Social engineering of staff or users
Physical security attacks
Vulnerabilities requiring non-standard browser plugins
Rate limit bypasses without security impact
Missing security headers with low impact

Program rules

Do not test on production data belonging to other users. Use your own test account for all research.

Do not disclose the vulnerability publicly until we've had 90 days to address it.

Do not perform DoS attacks, social engineering, or physical attacks.

One bounty per unique vulnerability. Duplicates receive acknowledgement only.

We respond to all valid reports within 5 business days and aim to resolve critical issues within 30 days.