Security researchers make Qoyla safer. If you have found a vulnerability, we want to hear about it, we promise to respond fast, act in good faith, and reward valid findings.
Test in good faith within these rules and we will not pursue legal action. We see you as a partner, not a threat.
We acknowledge reports within 1 business day and aim to triage within 3, with clear updates as we go.
Valid, in-scope findings earn a bounty scaled to severity, plus a place in our researcher hall of thanks.
Scope
Test only against accounts you own or have explicit permission to use. Never access, modify or exfiltrate another person's data, stop and report the moment you can demonstrate impact.
Rewards
Bounties scale with severity (CVSS) and the quality of your report. Clear, reproducible write-ups are paid faster and higher.
RCE, auth bypass, mass data exposure
Account takeover, significant IDOR
Stored XSS, sensitive info leak
Limited-impact issues, plus credit
Amounts are guidelines. Final awards depend on verified impact, and we run our programme through a managed platform with coordinated disclosure.
Report
The fastest route is our managed disclosure platform, it routes straight to our security team and tracks everything. Prefer email? Use our PGP-encrypted address.
A good report includes