PocketRN is thrilled to announce our approval as a participant in the groundbreaking CMMI GUIDE program.
Learn MorePocketRN is focused on ensuring the security of our customers' data. If you believe you have discovered a security or privacy vulnerability that affects PocketRN web services, databases, web servers, or cloud environment, please report it to us. We reward researchers who share with us critical issues and the techniques used to exploit them. It is a priority to resolve confirmed issues as quickly as possible.
Caregiver Account
To be eligible for a PocketRN Security Bounty, the issue must occur on the latest publicly available versions of the PocketRN web app with a standard configuration and, where relevant, on the latest publicly available hardware.
You must be the first party to report the issue to the PocketRN Security Team. A verifiable security vulnerability already reported but not yet closed will still be rewarded $10 for the submission.
You must Provide a clear report, which includes a working exploit (detailed below).
You must not disclose the issue publicly before PocketRN releases a public security report and fix for the bug.
Bounty payments are determined by the level of access or execution achieved by the reported issue (reduced if the quality of the report is insufficient). The exact payment amounts are determined after a review by PocketRN. All security issues with significant impact on users will be considered for PocketRN Security Bounty payment. Security Bounty payments are at PocketRN's discretion.
If we think believe your report has no reasonable vulnerability rating, we will not pay out any amount for the report. These include, but are not limited to, bugs that are exceedingly unlikely to occur or practically impossible to execute, user-controlled URL redirection, logout cross-site request forgery, self-hosted JavaScript, flaws impacting out-of-date browsers/OSes/etc., email spoofing, or third-party vulnerabilities we do not have direct control over.
The goal of the PocketRN Security Bounty is to protect customers by understanding both vulnerabilities and their exploitation techniques and technologies. Reports lacking the necessary information to enable PocketRN to efficiently reproduce the issue will result in a significantly reduced bounty payment if accepted at all.
A complete report includes:
I.e. we need sufficient information for PocketRN to be able to reasonably reproduce the issue in a timely manner.
Send your report by email to security@pocketrn.com. Whenever possible, encrypt all communications. Include all relevant videos, crash logs, and system diagnosis reports in your email. If necessary, contact us and ask about a drop location for large file uploads.
You will either be paid out in an Amazon Gift Card (up to $200) or via a Bill.com invoice. Before receiving the reward, you will be required to fill out a W9 form for accounting and tax purposes (or a W-8BEN if you are a foreign individual). You can access a W9 form here. or a W-8BEN here.
We're extremely grateful for your contributions in helping PocketRN be safe, secure, and protected. On behalf of our security team, thank you for your dedication to the hacking craft and community!