Bag Bounty Program
What we accept:
- vulnerabilities affecting user account security (authentication bypass, session hijacking, XSS, CSRF)
- payment logic flaws (double charging, incorrect balance credit, payment bypass)
- SQL injection, IDOR, other users' data leakage
- API vulnerabilities (for resellers)
What we do NOT accept:
- vulnerabilities in social networks and third-party services (Instagram, TikTok, etc.)
- DDoS, spam, brute-force attacks
- social engineering of our staff
- missing security headers without real impact
- vulnerabilities requiring physical access to a user's device
Rules:
- do not disclose vulnerability details until it is fixed
- do not damage other users' data
- use only your own account for testing
- one vulnerability = one report, duplicates are not paid
The reward is determined individually based on the severity and quality of the report. The first finder gets priority.
Service Improvement Program
We are always open to ideas that make the service more convenient.
What interests us:
- new features in the user dashboard and on the website
- interface and order-flow improvements
- new service types or social networks
- improvements to the API and reseller panel
- any ideas that will save time for you and other clients
How it works:
- describe the idea in as much detail as possible, with examples and screenshots
- we review each proposal within 7 business days
- if implemented, the author gets acknowledgment and a bonus to their balance
We do not guarantee that every idea will be implemented, but each one is personally reviewed by the team.
How to send a report or suggestion: click one of the buttons below. For authorized users, contacts are filled in automatically; guests can provide any email for communication.