Report Security Issues

If you have found a security vulnerability on our website, we encourage you to contact us immediately at support@kumfykids.com. We review all legitimate reports and aim to resolve issues quickly. Before reporting, please review this document, including our fundamentals, bounty program, reward guidelines, and non-reportable issues.

Fundamentals

If you follow the principles below when reporting a security issue to us, we will not initiate legal action or enforcement investigations against you in response to your report. We ask that you:

  • Give us reasonable time to review and fix the issue before disclosing it publicly or sharing it with others.
  • Do not interact with or access private accounts without the account owner's consent.
  • Make a good-faith effort to avoid privacy violations, service disruptions, or data destruction.
  • Do not exploit the issue for any reason, including to demonstrate further risks or access sensitive data.
  • Comply with all applicable laws and regulations.

Bounty Program

We recognize and reward security researchers who help protect our platform by reporting vulnerabilities. Bounties are awarded at our discretion, based on risk, impact, and report quality. To potentially qualify for a bounty, you must:

  • Follow the fundamentals listed above.
  • Report a valid security bug that poses a risk to privacy or security.
  • Submit your report through our security contact; please do not contact employees directly.
  • Disclose any accidental privacy violations or disruptions in your report.
  • Understand that while we investigate all valid reports, priority is based on risk and a response may take some time.

Rewards

Rewards are based on the impact and severity of the vulnerability. Please provide detailed and reproducible steps in your report. If the issue cannot be reproduced, it is not eligible for a bounty. The first valid report of an issue receives the bounty. Multiple bugs caused by a single underlying issue are treated as one report. Our current maximum reward amounts by severity are:

  • Critical Severity - $200: Remote code execution, remote shell or command execution, vertical authentication bypass, SQL injection that leaks targeted data, full account access.
  • High Severity - $100: Lateral authentication bypass, disclosure of sensitive internal data, stored XSS affecting other users, local file inclusion, insecure handling of authentication cookies.
  • Medium Severity - $50: Logic or business process flaws, insecure object references.
  • Low Severity - Recognition Only: Open redirects, reflected XSS, low-sensitivity information leaks.

Contact Information

Address: 5051 E 41st Ave, Denver, CO 80216, USA
Phone: +1 (212) 268-1100
Email: support@kumfykids.com