
Sheer
External Program
Submit bugs directly to this organization
While we are doing our best to keep Sheer as safe as possible, we know that some bugs can slip trough our scrutiny.
If you believe you've found a security issue in the services listed in our scope, we will work with you to resolve it promptly and ensure you are fairly rewarded for your discovery.
The scope of this program is limited to security vulnerabilities found on Sheer. Vulnerabilities reported on other properties or applications are currently not eligible for monetary reward. High impact vulnerabilities outside of this scope might be considered on a case by case basis.
https://www.sheer.com/ https://my.sheer.com/ https://www.sheer.com/chat
To get your creator account approved, please put a valid email, your login as first name and as last name : HackerOneBugBounty
Sheer may provide rewards to eligible reporters of qualifying vulnerabilities. Rewards amounts vary depending upon the severity of the vulnerability reported.
Sheer keeps the right to decide if the minimum severity threshold is met and whether the scope of the reported bug is actually already covered by a previously reported vulnerability. Rewards are granted entirely at the discretion of Sheer. To qualify for a reward under this program, you should respect all the below criterias.
We are happy to work with everyone who submits valid reports which help us improve the security of Sheer.
However, only those that meet the following eligibility requirements may receive a monetary reward:
Becareful, if your report requires the use of Burp Suite, there is a high chance that it is invalid. To avoid receiving a heavy penalty for a report classified as Invalid, please double-check multiple times that it is not a local hack (self-hack).
A good bug report should include the following information at a minimum:
We intend to respond and resolve reported issues as quickly as possible. This means that you will receive progress updates from us at least every five working days.
Note that posting details or conversations about the report or posting details that reflect negatively on the program and the Sheer brand, will result in immediate disqualification from the program.
Please note these are examples, and this list in non-exhaustive.
Vulnerabilities with a real security impact. Examples :
This type of issues can be accepted if they lead to a serious data leak.
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping keep Sheer and our users safe!