← SherpaCarta

Security & Bug Bounty

Responsible disclosure · Safe harbor for good-faith research

SherpaCarta practices extreme privacy by design. We welcome security researchers who help us keep the charter and site safe for everyone.

Report a vulnerability

Email: hello@giveabit.io

Include: description, reproduction steps, impact assessment, and your preferred disclosure timeline.

Safe harbor

Good-faith security research that follows this policy will not face legal action from Give A Bit, provided you:

Scope

In scope:

Out of scope: Third-party CDNs, social engineering, physical attacks, spam.

Reward tiers

Critical (RCE, fund theft, mass data leak)Recognition + priority fix + public thanks
High (XSS, auth bypass, signature forgery)Recognition + public thanks
Medium (CSRF, info disclosure)Hall of fame acknowledgment
Low (minor issues, best practices)Acknowledgment

SherpaCarta is a volunteer-funded movement. Rewards are recognition-based until a formal bounty fund is established.

Disclosure timeline

  1. Report to hello@giveabit.io
  2. Acknowledgment within 5 business days
  3. Fix timeline based on severity
  4. Coordinated public disclosure with reporter

Hall of fame

No public reports yet. Be the first to help protect digital rights for 8 billion people.

Also see security.txt · Treasury