Bypass.io Vulnerability Disclosure Policy
Last Updated: July 6, 2026
Security is core to what we do at Bypass.io (the “Company,” “we,” “us,” or “our”). We operate a premium proxy platform — residential, static residential (ISP), datacenter, and LTE/mobile proxies — along with the web app at https://bypass.io, the customer dashboard at https://dashboard.bypass.io, and our public API. Protecting that platform and the data our customers entrust to us is a responsibility we take seriously.
We value the work of the security research community, and we welcome good-faith reports of vulnerabilities that could affect our services. This policy explains what is in scope, how to test responsibly, how to report to us, what you can expect in return, and the legal safe harbor we extend to researchers who act in accordance with these terms.
1. Our Commitment
We are committed to working openly and constructively with researchers. Specifically, we will:
- Investigate every good-faith report we receive under this policy.
- Respond promptly and keep you informed as we triage and remediate.
- Extend the safe harbor described in Section 8 to research conducted within the boundaries of this policy.
- Recognize your contribution — publicly, if you wish — once an issue is confirmed and resolved.
In return, we ask that you give us a reasonable opportunity to fix an issue before disclosing it publicly, and that you follow the rules of engagement below.
2. In-Scope Targets
The following assets that we own and operate are in scope for testing under this policy:
- Public website / web app: bypass.io (and www.bypass.io)
- Customer dashboard: dashboard.bypass.io
- API: api.bypass.io
- Authentication, billing, and account-management flows exposed through the assets above (for example, sign-up, login, password reset, balance top-ups, and order provisioning).
Vulnerability classes we are most interested in include authentication and authorization flaws, broken access controls (including IDOR and tenant isolation issues), server-side request forgery, injection (SQL, command, template), server-side remote code execution, sensitive data exposure, and payment or balance-manipulation logic flaws.
3. Out-of-Scope Targets and Findings
To keep our platform stable for customers and to respect the systems of others, the following are out of scope. Please do not test them under this policy:
- Upstream proxy networks and provider infrastructure.Our proxy pools are sourced from third-party upstream networks. Their infrastructure, IP ranges, and exit nodes are not ours to authorize testing on — do not target, scan, or attempt to exploit them.
- Third-party services and vendorswe rely on but do not control — for example, our payment processor, transactional email provider, cloud hosting/CDN, and anti-abuse/CAPTCHA providers. Report suspected issues to the relevant vendor, or to us so we can coordinate.
- Denial-of-service (DoS/DDoS) and volumetric attacks of any kind, including resource-exhaustion and application-layer flooding.
- Social engineering against our staff, customers, partners, or vendors (phishing, vishing, pretexting, and similar).
- Physical attacks against our offices, staff, or data-center facilities.
- Automated scanner noise and output from automated tools without a demonstrated, exploitable impact.
- Brute-force, credential-stuffing, and rate-limit testing that generates excessive traffic.
The following report types are generally considered informational and, on their own, are unlikely to be treated as actionable vulnerabilities:
- Descriptive error messages, stack traces, or version banners without a proven exploit.
- Disclosure of public or non-sensitive files, e.g. robots.txt.
- Known issues in outdated third-party libraries without a working proof-of-concept.
- Missing security headers or best-practice recommendations with no demonstrable impact.
- Email configuration findings (SPF, DKIM, DMARC) and clickjacking on pages with no sensitive state-changing actions.
- CSRF on logout or other non-sensitive, low-impact endpoints.
- Username or account enumeration and verbose login error messages.
- Self-XSS that cannot be used to attack another user.
- Reports about rate limiting or lack thereof, absent a concrete security impact.
If you believe an out-of-scope or informational item chains into a real, higher-severity issue, tell us — we would rather hear about it than not.
4. Rules of Engagement
When you research under this policy, you must act in good faith and minimize harm. Concretely:
- Do no harm to data. Do not access, download, modify, delete, or destroy data that is not yours, and do not exfiltrate data of any kind.
- Respect privacy.If you inadvertently encounter another person’s personal data, credentials, or confidential information, stop immediately, do not save or share it, and tell us in your report.
- Use test accounts. Register and use your own accounts and test data. Do not interact with, pivot to, or target accounts you do not own.
- Stop at proof-of-concept. Once you have demonstrated a vulnerability, stop. Do not escalate access, pivot to other systems, or run further exploitation than is necessary to prove impact.
- Protect availability. Do not run tests that degrade, disrupt, or overload our services or those of our customers, upstream providers, or vendors.
- Stay in scope. Test only the in-scope targets in Section 2. If you are unsure whether something is in scope, ask us at [email protected] before proceeding.
- Keep it confidential. Give us a reasonable time to remediate before any public disclosure, and coordinate disclosure with us (see Section 7).
5. How to Report
Send security reports by email to [email protected]. This is the primary and preferred channel for all security matters. For reports of active abuse of our proxies (rather than a vulnerability in our platform), you may instead contact [email protected].
A high-quality report helps us triage and fix faster. Please include:
- Summary: a clear, concise description of the vulnerability and the affected asset or endpoint.
- Reproduction steps: precise, step-by-step instructions to reproduce the issue, including the exact URLs, parameters, and any accounts used.
- Impact: what an attacker could achieve, and why it matters.
- Proof-of-concept: supporting evidence such as request/response captures, screenshots, logs, or a short (non-destructive) PoC. Please redact any real personal data.
- Environment: relevant details such as browser, client, or tooling, and the approximate date and time of testing.
- Contact and recognition: how you would like to be credited, if at all.
You may report anonymously. If you would like a response or public credit, please include a way to reach you.
6. Our Response Process and Target Timelines
We handle reports on a best-effort basis and aim to meet the following targets. These are goals, not contractual commitments, and may vary with severity and complexity:
- Acknowledge — within 3 business days. We confirm we have received your report and assign it for review.
- Triage — within 7 business days. We validate the issue, assess its severity and impact, and let you know whether it is confirmed, a duplicate, out of scope, or needs more information.
- Remediate. We prioritize and fix confirmed issues based on severity and risk. We will keep you updated on our progress and may reach out for clarification or to verify a fix.
- Coordinated disclosure. Once a fix is deployed, we will work with you on the timing and content of any public disclosure (see Section 7).
7. Coordinated Disclosure
We ask that you keep the details of any vulnerability confidential until we have remediated it and agreed with you on a disclosure timeline. Premature disclosure can put our customers and their data at risk.
- We will make a good-faith effort to remediate valid issues promptly and to coordinate a disclosure timeline with you.
- Where you wish to publish, we are happy to review a draft, correct any inaccuracies, and agree on a mutually acceptable publication date.
- Please do not disclose customer data, our internal systems, or the specifics of an unpatched vulnerability at any point.
8. Legal Safe Harbor
We want you to feel confident reporting to us. If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, and:
- We will not initiate or recommend legal action against you in connection with your research, including under applicable computer-misuse or anti-hacking laws or our Terms of Service.
- We will treat your activity as authorized conduct with respect to any applicable anti-circumvention provisions.
- If a third party brings legal action against you for activity that was conducted in accordance with this policy, we will take reasonable steps to make it known that your actions were authorized under this policy.
This safe harbor applies only to research that stays within this policy. It does not authorize actions that are inconsistent with these terms — for example, accessing or exfiltrating data that is not yours, disrupting our services, or targeting out-of-scope systems (including our upstream providers and third-party vendors). If in doubt about whether your intended testing is covered, contact us at [email protected] before you begin, and we will work with you in good faith.
9. Recognition and Rewards
We do not currently operate a formal, published bug-bounty program, and we make no promise of payment for any report. That said, we genuinely value the community’s work:
- Recognition. With your consent, we are happy to credit you for a valid, responsibly disclosed and resolved report.
- Discretionary rewards. We may, entirely at our discretion, offer a reward for a particularly high-impact or well-documented report. Any such reward, its form, and its amount are decided case by case and are not guaranteed.
If we introduce a formal bounty program in the future, we will announce it and update this page.
10. Changes to This Policy
We may update this policy from time to time to reflect changes in our services, scope, or process. The current version always governs; the “Last Updated” date above indicates when it last changed. We encourage researchers to review this page before beginning any testing.
11. Contact
For all security matters — to report a vulnerability, ask a scoping question, or coordinate disclosure — contact our security team at [email protected]. For proxy abuse reports, use [email protected]. For general or legal inquiries, use [email protected], and for privacy-specific questions, [email protected].