Security
Bug Bounty Program
We take security seriously. If you discover a vulnerability in KumoBuilder, we want to hear from you — and we reward responsible disclosure.
Reward tiers
Critical
RCE, auth bypass, mass data exfiltration, cross-tenant data access
$500–$2,000
High
Privilege escalation, significant PII leak, stored XSS
$200–$500
Normal
CSRF, reflected XSS, sensitive data in logs, insecure direct object reference
$50–$200
Low
Minor information disclosure, UI redressing, low-impact misconfigurations
Acknowledgement
In scope
✓kumobuilder.com and all subdomains
✓API endpoints (api.kumobuilder.com)
✓Authentication & session management
✓Multi-tenant data isolation
✓AI pipeline endpoints
✓Website generation endpoints
✓Admin panel (admin.kumobuilder.com)
Out of scope
✕Third-party services and dependencies
✕DoS / DDoS attacks
✕Social engineering of staff or users
✕Physical security attacks
✕Vulnerabilities requiring non-standard browser plugins
✕Rate limit bypasses without security impact
✕Missing security headers with low impact
Program rules
Do not test on production data belonging to other users. Use your own test account for all research.
Do not disclose the vulnerability publicly until we've had 90 days to address it.
Do not perform DoS attacks, social engineering, or physical attacks.
One bounty per unique vulnerability. Duplicates receive acknowledgement only.
We respond to all valid reports within 5 business days and aim to resolve critical issues within 30 days.