Stormrake Bug Bounty Program
Security is at the heart of everything we do. We invite security researchers to responsibly disclose vulnerabilities in the Stormrake Client Portal — and we reward valid findings.
Rewards & Eligibility
What you can earn
Rewards are assessed by severity using the CVSS framework:
Critical
AUD $2,000 – $5,000
High
AUD $1,000 – $2,000
Medium
AUD $300 – $1,000
Low
AUD $50 – $300
Eligibility
- You must be the first person to report the vulnerability
- Stormrake employees and contractors are not eligible
- Limit any exploitation to a minimal proof of concept — never access, modify or destroy data that isn’t yours
- You must comply with all applicable local laws
Scope
What's in and out of scope
In Scope
- app.stormrake.com (the Stormrake Client Portal)
- APIs and services associated with the Client Portal
Vulnerabilities We Want to Hear About
- Authentication bypass and session-handling flaws
- Cross-site scripting (XSS) and cross-site request forgery (CSRF)
- Privilege escalation and insecure direct object references (IDOR)
- SQL injection and server-side request forgery (SSRF)
Out of Scope
- The marketing website (www.stormrake.com)
- Social engineering of staff or customers
- Denial-of-service (DoS) attacks
- Reports generated solely by automated scanners
- Issues that only affect outdated browsers
- Missing security headers without a demonstrable impact
How to Participate
Reporting a vulnerability
- Email your finding to security@stormrake.com
- Include clear reproduction steps and a proof of concept
- Allow up to 10 business days for our team to review and respond
- Do not publicly disclose the issue before it has been resolved
Send reports to security@stormrake.com.
Thank you
We're grateful to the security research community for helping keep Stormrake and our clients safe. Every valid report makes the platform stronger — thank you for disclosing responsibly.