Bug bounty program
Find security issues in Lumin to earn rewards and secure your spot in our Hall of Fame through our vulnerability disclosure program.
Table of contents
- Policy
- Rewards
- Rules for reporting
- In scope
- Out of scope
- What we are looking for
- What we are not looking for
Policy
The following guidelines give you an idea of what we usually pay out for different classes of security issues. Low-quality issues may be rewarded below these tiers, so please make sure that there is enough information for us to be able to reproduce your issue and step-by-step instructions including how to reproduce your issue. Screenshots are also helpful, but please make sure to not make these public before submitting them to follow our program’s rules.
Rewards
| Security vulnerability | Mobile crash/ANR | ||||
|---|---|---|---|---|---|
| Most critical | Critical | High | Medium | Low | |
| 600 USD - 1200 USD | 400 USD - 600 USD | 200 USD | 100 USD | 50 USD | 500 USD |
| Security vulnerability | |
|---|---|
| Most critical | Critical |
| 600 USD - 1200 USD | 400 USD - 600 USD |
| High | Medium |
|---|---|
| 200 USD | 100 USD |
| Low |
|---|
| 50 USD |
| Mobile crash/ANR |
|---|
| 500 USD |
Rules for reporting
- Report a qualifying vulnerability that is in the scope of our program (below).
- Be the first person to report the vulnerability.
- Be reasonable with automated scanning methods so as to not degrade services.
- Refrain from disclosing the vulnerability until we've addressed it.
- NEVER try to gain access to a real user's account or data.
- You must not leak, manipulate, or destroy any user data.
- Do not impact users with your testing.
- For mobile crashes/ANRs: include the device model, OS version (Android/iOS), and Lumin app version. Share relevant crash logs or recordings if possible.
In scope
- app.luminpdf.com
- luminpdf.com
- Android & iOS applications
- sign.luminpdf.com
Out of scope
What we are looking for
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Insecure direct object reference (IDOR)
- Account takeovers
- SQL injection
- Authentication flaws
- Remote code execution (RCE)
- Server-side request forgery (SSRF)
- XML External Entity Attacks (XXE)
- Crashes or ANRs on the mobile app
- Anything not listed but important
What we are not looking for
- Vulnerabilities requiring physical access to the victim's unlocked device
- Denial of Service attacks
- Brute force attacks
- Spam or social engineering techniques
- Content spoofing
- Best practices concerns
- Issues relating to password policy
- Issues relating to token lifetime
- User enumeration
- Full path disclosure on any property
- CSRF-able actions that do not require authentication (or a session) to exploit
- Reports related to missing security headers
- CSV injection
- Reverse tabnabbing
- Bugs that do not represent any security risk
- Crashes and ANR issues that are not reproducible
- Vulnerabilities that are limited to unsupported browsers
How to report?
Please send all security reports to [email protected]
Learn more about Lumin security
Lumin has a robust, modern security system. We focus on customized security solutions in conjunction with industry-standard compliance.
Explore security center