🌏 Private Box Limited Bug Bounty Program Policy
1. Introduction
This policy outlines the guidelines and procedures for our Bug Bounty Program. We are committed to protecting our users and data, and we believe that working with the security research community is crucial to achieving this goal. This program provides a framework for security researchers to report vulnerabilities found in our systems and services responsibly.
2. Scope
The scope of this bug bounty program includes the following:
Any systems or services not explicitly listed above are out of scope.
3. Responsible Disclosure Guidelines
We ask all security researchers to adhere to the following guidelines when participating in our program:
4. Reporting a Vulnerability
To report a vulnerability, please send a detailed report to gareth@privatebox.co.nz or support@privatebox.co.nz. Your report should include:
5. Rewards
We will review all valid vulnerability reports and offer rewards based on the severity and impact of the vulnerability. The decision to award a bounty and the amount of the bounty are at our sole discretion.
Please note: vulnerabilities found on www.privatebox.co.nz are eligible for a fixed reward of $50 USD, regardless of severity. This fixed reward applies only to valid, bounty-eligible security vulnerabilities and does not override the non-qualifying findings listed below.
Severity | CVSS (v3.1 Base Score) | Example Vulnerabilities | Reward (other domains, in NZD) |
Critical | 9.0 - 10.0 | Remote Code Execution, SQL Injection (authenticated/unauthenticated), Auth Bypass | $1,500 - $3,000 |
High | 7.0 - 8.9 | Cross-Site Scripting (persistent), CSRF with significant impact, Sensitive Data Exposure | $500 - $1,500 |
Medium | 4.0 - 6.9 | Cross-Site Scripting (reflected), Open Redirect, Information Disclosure | $150 - $500 |
Low | 0.1 - 3.9 | Self-XSS, Non-sensitive Information Disclosure | $50 - $150 |
CVSS (Common Vulnerability Scoring System) provides an open and standardised method for rating IT vulnerabilities.
6. Non-qualifying / low-impact findings
The following findings are generally not eligible for a bounty unless they demonstrate material security impact:
7. Legal
By submitting a vulnerability report, you agree to these terms and conditions. We reserve the right to modify or terminate this program at any time.
8. Contact Information
For any questions regarding this policy or our Bug Bounty Program, please contact gareth@privatebox.co.nz or support@privatebox.co.nz.
8. Updates
This policy was last updated on 19th of June 2026. Please check this page regularly for any updates.