Skip to content

You're viewing content for the United States. Select your region for information relevant to your location.

Stormrake

Stormrake Bug Bounty Program

Security is at the heart of everything we do. We invite security researchers to responsibly disclose vulnerabilities in the Stormrake Client Portal — and we reward valid findings.

What you can earn

Rewards are assessed by severity using the CVSS framework:

Critical

AUD $2,000 – $5,000

High

AUD $1,000 – $2,000

Medium

AUD $300 – $1,000

Low

AUD $50 – $300

Eligibility

  • You must be the first person to report the vulnerability
  • Stormrake employees and contractors are not eligible
  • Limit any exploitation to a minimal proof of concept — never access, modify or destroy data that isn’t yours
  • You must comply with all applicable local laws

What's in and out of scope

In Scope

  • app.stormrake.com (the Stormrake Client Portal)
  • APIs and services associated with the Client Portal

Vulnerabilities We Want to Hear About

  • Authentication bypass and session-handling flaws
  • Cross-site scripting (XSS) and cross-site request forgery (CSRF)
  • Privilege escalation and insecure direct object references (IDOR)
  • SQL injection and server-side request forgery (SSRF)

Out of Scope

  • The marketing website (www.stormrake.com)
  • Social engineering of staff or customers
  • Denial-of-service (DoS) attacks
  • Reports generated solely by automated scanners
  • Issues that only affect outdated browsers
  • Missing security headers without a demonstrable impact

Reporting a vulnerability

  1. Email your finding to security@stormrake.com
  2. Include clear reproduction steps and a proof of concept
  3. Allow up to 10 business days for our team to review and respond
  4. Do not publicly disclose the issue before it has been resolved

Send reports to security@stormrake.com.

Thank you

We're grateful to the security research community for helping keep Stormrake and our clients safe. Every valid report makes the platform stronger — thank you for disclosing responsibly.