Published using Google Docs
Bug Bounty Program Policy
Updated automatically every 5 minutes

🌏 Private Box Limited Bug Bounty Program Policy

1. Introduction

This policy outlines the guidelines and procedures for our Bug Bounty Program. We are committed to protecting our users and data, and we believe that working with the security research community is crucial to achieving this goal. This program provides a framework for security researchers to report vulnerabilities found in our systems and services responsibly.

2. Scope

The scope of this bug bounty program includes the following:

Any systems or services not explicitly listed above are out of scope.

3. Responsible Disclosure Guidelines

We ask all security researchers to adhere to the following guidelines when participating in our program:

4. Reporting a Vulnerability

To report a vulnerability, please send a detailed report to gareth@privatebox.co.nz or support@privatebox.co.nz. Your report should include:

5. Rewards

We will review all valid vulnerability reports and offer rewards based on the severity and impact of the vulnerability. The decision to award a bounty and the amount of the bounty are at our sole discretion.

Please note: vulnerabilities found on www.privatebox.co.nz are eligible for a fixed reward of $50 USD, regardless of severity. This fixed reward applies only to valid, bounty-eligible security vulnerabilities and does not override the non-qualifying findings listed below.

Severity

CVSS (v3.1 Base Score)

Example Vulnerabilities

Reward (other domains, in NZD)

Critical

9.0 - 10.0

Remote Code Execution, SQL Injection (authenticated/unauthenticated), Auth Bypass

$1,500 - $3,000

High

7.0 - 8.9

Cross-Site Scripting (persistent), CSRF with significant impact, Sensitive Data Exposure

$500 - $1,500

Medium

4.0 - 6.9

Cross-Site Scripting (reflected), Open Redirect, Information Disclosure

$150 - $500

Low

0.1 - 3.9

Self-XSS, Non-sensitive Information Disclosure

$50 - $150

CVSS (Common Vulnerability Scoring System) provides an open and standardised method for rating IT vulnerabilities.

6. Non-qualifying / low-impact findings

The following findings are generally not eligible for a bounty unless they demonstrate material security impact:

7. Legal

By submitting a vulnerability report, you agree to these terms and conditions. We reserve the right to modify or terminate this program at any time.

8. Contact Information

For any questions regarding this policy or our Bug Bounty Program, please contact gareth@privatebox.co.nz or support@privatebox.co.nz.

8. Updates

This policy was last updated on 19th of June 2026. Please check this page regularly for any updates.