Bug Bounty Program
UnoLock values security researchers and the security community. This program focuses on exploitable security vulnerabilities that materially threaten the confidentiality, integrity, or recoverability of user data. Only validated High or Critical findings meeting the eligibility rules below are considered for discretionary monetary rewards. Other reports remain welcome under our Vulnerability Policy, without a monetary reward.
Reward Structure
| Severity | Reward Range | Examples |
|---|---|---|
| Tier 1: Critical | $500 - $1,000 AUD | Practical compromise of Safe contents or encryption keys, or widespread unauthorized destruction of user data |
| Tier 2: High | $200 - $500 AUD | Demonstrated unauthorized access, disclosure, modification, or deletion of protected user data with narrower scope or additional attack prerequisites |
| Tier 3: Medium | No monetary reward | Limited-impact security findings that do not meet the High/Critical user-data impact threshold |
| Tier 4: Low | No monetary reward | UI defects, minor information leaks, and best-practice recommendations |
Important: All reward amounts are at UnoLock's sole discretion based on severity, impact, quality of report, and current budget availability. The ranges are guidance for approved awards, not a minimum payment or a promise of payment. The maximum aggregate reward is $1,000 AUD per unique root cause.
Platforms In Scope
- UnoLock Web App (PWA): https://safe.unolock.com
- Windows Store App: Desktop application
- API Endpoints: UnoLock-controlled APIs used by the in-scope applications
Out of Scope Platforms
- https://app.unolock.com is excluded from this program; testing on that host is not authorized by this policy and findings on it are not eligible for rewards.
- Third-party services themselves (AWS, Stripe, Google Workspace); qualifying flaws in UnoLock-controlled integrations remain eligible
- Mobile apps (not yet launched)
- Browser extensions (don't exist)
Reward Eligibility: Demonstrated User-Data Risk
A report must meet all of the following requirements to be considered for a monetary reward:
- Identify a reproducible vulnerability in a current, supported UnoLock application or UnoLock-controlled API within the platform scope above.
- Demonstrate a realistic attack path across a security boundary, including prerequisites, required privileges, and user interaction. A vulnerability category or scanner severity alone does not establish eligibility.
- Show material unauthorized access to or disclosure of protected user data, exposure of encryption keys or recovery secrets, unauthorized modification or deletion of user data, or an exploitable loss of legitimate data recovery.
- Be assessed by UnoLock as High or Critical based on demonstrated user impact, exploitability, and affected scope.
- Be the first valid report of the root cause and comply with the testing and coordinated disclosure rules.
Use only your own test Safes and synthetic data, including separate attacker and victim test Safes where needed. You do not need to compromise a real user to demonstrate impact. Do not access other users' data or perform destructive production testing.
Business-logic, payment, subscription, quota, or licensing flaws qualify only if a demonstrated exploit chain independently meets the High/Critical user-data impact requirements. Lost revenue, unpaid feature access, or increased operating costs alone do not qualify.
Sensitive metadata disclosure can qualify when it demonstrates a material privacy breach, such as linking an identity to a private Safe or exposing confidential relationships. Public identifiers, endpoint discovery, or generic technical metadata alone do not qualify.
Tier 1: Critical Security Issues ($500 - $1,000 AUD)
Examples include practical compromise of Safe contents or keys with few prerequisites, or widespread unauthorized destruction of protected user data:
- Authentication or authorization bypass that gives an attacker access to another user's Safe contents or secrets.
- A cryptographic or key-management flaw that exposes plaintext, encryption keys, recovery secrets, or stored cryptocurrency private keys.
- A cross-Safe isolation failure enabling broad unauthorized reading, modification, or deletion of user data.
Examples are illustrative; the demonstrated attack and impact determine severity and eligibility.
Tier 2: High Security Issues ($200 - $500 AUD)
Examples include material compromise of protected user data with narrower scope or additional attack prerequisites:
- XSS, session hijacking, or CSRF that demonstrably enables unauthorized reading, modification, or deletion of Safe data or changes to data-access permissions.
- Authorization or encryption failures exposing files, Vault Messaging content, UnoLock Drop transfers, or private shared-Space data.
- LegacyLink, recovery, or access-control flaws that grant unauthorized access or let an attacker irreversibly prevent legitimate recovery of protected data.
- Client-side flaws exposing protected plaintext or secrets after a Safe closes, or leaking them to an unauthorized party while it is open.
Observing your own decrypted data in an unlocked Safe or changing your own browser state does not establish an unauthorized-access vulnerability. Show how an attacker can cross the relevant security boundary.
Tier 3: Medium Issues (No Monetary Reward)
Validated issues below the High/Critical user-data impact threshold may be investigated and fixed, but are not eligible for payment.
Tier 4: Low/Informational Issues (No Monetary Reward)
Minor security observations, best-practice recommendations, and product defects are welcome as feedback, but are not eligible for payment.
Not Eligible for Monetary Rewards
Reward exclusions do not prevent responsible reporting or remove safe-harbor protection for testing that complies with the applicable rules. Prohibited testing remains prohibited.
Business and Low-Impact Issues
- Payment or subscription bypass, unpaid premium features, tier or license bypass, coupon abuse, storage/quota overages, and other revenue-only or operating-cost issues without qualifying user-data impact.
- UI/UX defects, broken buttons, rendering failures, compatibility issues, and ordinary reliability bugs without an exploitable security boundary failure.
- Missing headers, CSP or SRI recommendations, version banners, verbose errors, exposed endpoint names, and automated scanner or dependency alerts without a demonstrated qualifying exploit.
- Rate-limit observations, theoretical attacks, self-XSS, and clickjacking without demonstrated High/Critical user-data impact.
Infrastructure
- Vulnerabilities in AWS services themselves; UnoLock-controlled configuration or integration flaws remain eligible if they meet the user-data impact requirements
- Stripe payment processor vulnerabilities
- Google Workspace vulnerabilities
- Third-party CDN or hosting issues
Attack Types
- Denial of Service (DoS/DDoS) attacks
- Social engineering (phishing, pretexting)
- Physical attacks (device theft, shoulder surfing)
- Client device compromises (malware, memory scraping, privileged forensic tools) that only read plaintext while the Safe is open and never cause data to leave the device
- Timing or side-channel attacks (cache timing, electromagnetic analysis, etc.)
- Brute force attacks without demonstrating rate limiting bypass
- Self-XSS (user pasting malicious code into their own vault)
Non-Security Issues
- Typos or grammatical errors
- Feature requests
- UI/UX improvements without security impact
- Browser compatibility issues
Previously Disclosed Issues
- Vulnerabilities already reported by another researcher
- Issues publicly disclosed before private reporting
- Duplicate reports
How to Submit a Vulnerability
1. Email: security@unolock.com
2. Use PGP Encryption (Recommended): Download our PGP public key
Report Should Include:
- Vulnerability Description: Clear explanation of the security issue
- Impact Assessment: The protected data at risk, security boundary crossed, realistic attack prerequisites, and demonstrated result using your own test data
- Reproduction Steps: Detailed step-by-step instructions to reproduce
- Proof of Concept: Code, screenshots, or video demonstration
- Affected Components: URL, API endpoint, or feature affected
- Suggested Fix: (Optional) How to remediate the vulnerability
Response Timeline
| Initial Response: | Target: within 48 hours of submission |
| Validation & Triage: | Target: 7 days for critical, 30 days for high |
| Fix Timeline: | Target: 7 days for critical, 30 days for high; other reports prioritized by impact |
| Reward Payment: | For approved awards: target within 30 days after fix deployment and receipt of payment details |
Rules of Engagement
You May:
- Create test accounts/vaults for research purposes
- Test on your own data only
- Use automated tools with rate limiting respect
- Test all in-scope platforms and features
- Report vulnerabilities confidentially
You Must Not:
- Access, modify, or delete other users' vaults or data
- Perform denial of service attacks
- Spam or abuse the platform
- Social engineer UnoLock employees or users
- Publicly disclose vulnerabilities before fix deployment
- Violate any laws or regulations
Safe Harbor
UnoLock commits to the following safe harbor for security researchers who:
- Follow the rules of engagement outlined above
- Report vulnerabilities responsibly to security@unolock.com
- Give us reasonable time to fix before public disclosure
- Do not exploit vulnerabilities beyond proof of concept
- Do not access, modify, or delete other users' data
We will not pursue legal action against researchers who comply with these terms. We consider good-faith security research conducted under this program to be authorized testing.
Payment Methods
If a monetary reward is approved in writing, payment can be arranged after validation and fix deployment via:
- Bitcoin: Available for anonymous payments
- Wire Transfer: Available for large rewards (>$500 AUD)
Tax Responsibility: Researchers are responsible for any tax obligations in their jurisdiction.
Important Terms
Discretionary Rewards
All reward amounts are at UnoLock's sole discretion based on:
- Severity of impact
- Quality of report and reproduction steps
- Whether issue is in scope
- Whether issue is a duplicate
- Current budget availability
First Come, First Served
Only the first valid report of a unique root cause is eligible. Variants of the same root cause across endpoints, platforms, affected Safes, or exploit techniques are treated as one finding, with one aggregate reward capped at $1,000 AUD. Splitting a report does not create additional reward eligibility.
Budget Cap
UnoLock reserves the right to pause the bug bounty program if the annual budget is reached. Any resumption will be announced on this page. Responsible disclosure remains open while rewards are paused. Awards already approved in writing will be honored.
Reward Ranges
Reward amounts listed are ranges, not guaranteed payments. Eligibility and any award are determined after validation and impact assessment, subject to available budget. Submission, acknowledgment, validation, or remediation alone does not guarantee payment; an award requires written confirmation from UnoLock.
Program Changes
UnoLock reserves the right to modify or terminate this program with 30 days notice. Revised reward terms apply to reports first submitted on or after the announced effective date; earlier reports are assessed under the terms in effect when first submitted. Awards already approved in writing will be honored.
Questions About This Program?
Security Team: security@unolock.com
PGP Public Key: unolock.com/.well-known/pgp-key.txt
General Support: support@unolock.com
Last Updated: September 8, 2026
Program Status: Active
Annual Budget Remaining: Undisclosed