Dedicated Mobile Proxies logo
Security

Responsible disclosure & bug bounty policy

If you discover a vulnerability in Dedicated Mobile Proxies, please let us know about it. This page explains what is in scope, what we pay for and do not pay for, and how to report, so that both sides avoid surprises.

Scope

In scope

  • This website, dedicatedmobileproxies.com
  • The customer dashboard reached by signing in, and its API
  • The handling of rotation links, API keys and proxy credentials in the dashboard

Out of scope

  • Proxy gateways, modem hosts and the mobile carrier networks that support them
  • Services third parties operate, such as payment processors, Telegram, Cloudflare and email providers
  • Marketing assets served from legacy CDN paths
  • Any customer account or data that does not belong to you

What we pay

We give rewards for impact that is demonstrated on our systems or our customers. Amounts are in USD.

Critical
$100 – $250
  • Remote code execution on our servers
  • SQL injection by which customer data is read or written
  • Any account entered without its credentials by bypassing authentication
  • Manipulation of payments or balances to receive proxies, credit or refunds without paying
  • Proxy credentials or personal data of other customers being exposed in bulk
High
$50 – $100
  • Reading or altering the proxies, orders or account details of another customer (IDOR)
  • Stored cross-site scripting that executes within the session of an admin or of another customer
  • Privilege escalation where a customer account obtains access to admin functions
  • Server-side request forgery reaching internal services
  • Stealing the API key, rotation link or session of a different account
Medium
$20 – $50
  • Cross-site request forgery affecting an action that updates account state
  • Reflected cross-site scripting requiring that the victim click a link
  • Bypassing a rate limit where this is shown to lead to account takeover
  • Errors in pricing or business logic where you demonstrate a financial impact
Low / Informational
$0

You get an acknowledgment and, where warranted, a fix, not a payment. You will find the full list below, so you can check it before writing your report.

What we do not pay for

We will accept these at Low or Informational severity at most. We will read each one and fix whatever is worth fixing, but no bounty is issued, and marking the report Critical or High does not alter that.

  • A session that is not closed when you log out, change or reset your password, and stays valid until the token expires
  • Security headers such as CSP, HSTS, X-Frame-Options or Referrer-Policy being missing or “weak”, without a working exploit
  • Clickjacking on pages where no sensitive action can be taken
  • Attributes set on cookies that do not carry the session
  • Telling which emails or usernames are registered, even through timing or error messages
  • Observations about forgot-password, login or rate limiting that come without a demonstrated account takeover
  • Opinions regarding password policy, including length, complexity, common-password lists, no forced rotation
  • Two-factor authentication not being available, or 2FA not being compulsory
  • Self-XSS, or XSS that can be triggered only by the attacker in the attacker's own session
  • CSRF on login, logout, language and other forms without sensitive actions
  • Open redirects that do not reveal a token or credential
  • Disclosure of a software version, server banner, stack trace or path where no sensitive data is exposed
  • SPF, DKIM or DMARC configuration reports
  • Findings from automated scanners not supported by a proof of concept
  • Denial of service, exhausting resources, brute force, or any test that creates load
  • Social engineering or phishing that targets our staff or our customers; physical attacks
  • Issues that belong to third parties we use, including payment processors, Telegram, Cloudflare and email providers
  • Library versions that are out of date, without a working exploit against our deployment
  • Attacks that cannot work without a compromised device, a rooted phone or a man-in-the-middle position
  • Recommendations about best practice, theoretical risks, and duplicates of issues already on record

How to report

Email [email protected] with the subject Security report. Each report needs the affected URL, exact steps to reproduce, the account you used, and a proof of concept. We will acknowledge your report within 5 business days and give you a severity decision within 10 business days.

Machine-readable contact details are at /.well-known/security.txt.

Send a report

Policy last updated 2026-10-10.

Rules of engagement

  1. First valid report wins. A report that duplicates another, or covers a known issue, is not paid. Every root cause receives one payment, however many endpoints it may affect.
  2. Prove it, then stop. Access only your own accounts and data. Where a test would expose data belonging to someone else, stop at the first proof and report it, and do not pivot, download or persist.
  3. Do not degrade the service. We do not allow load testing, automated fuzzing at volume, or tests against proxy gateways, modem hosts or carrier networks. Those are out of scope entirely.
  4. Give us time. We ask that you not publish until the issue is fixed and 30 days have passed. You will be told by us when a fix is live.
  5. Severity is ours to set. We assess the impact on our own systems, guided by the Bugcrowd Vulnerability Rating Taxonomy as the reference. Payment amounts sit within the ranges above at our discretion, and we pay them by PayPal or USDT.
Safe harbour. Research that follows these rules is authorised. You are protected from legal action by us when you test in good faith within scope, and we ask that you show the same good faith to us: no extortion, no threats of disclosure, no “pay first, details later”.