Vulnerability Disclosure & Bug Bounty Program
Last updated: August 2026
Battle Planner values responsible security research and appreciates the efforts of researchers who help improve the security and reliability of our platform. This page explains how to responsibly report security vulnerabilities, what types of reports are eligible, and how we work with researchers during investigation and remediation.
1. Program Goals
This program is intended to:
- Encourage responsible security research
- Improve platform security and reliability
- Provide a clear process for vulnerability reporting
- Protect users and platform infrastructure
- Foster collaboration with the security community
2. In-Scope Systems
Unless otherwise stated, this program applies to publicly accessible Battle Planner systems and services, including:
- Web application and authentication systems
- Task and list management system
- Workspace collaboration features and access controls
- File attachment and storage system
- Notification and real-time sync infrastructure
- Public-facing APIs and integrations
3. Eligible Vulnerabilities
Examples of potentially eligible vulnerabilities may include:
- Authentication bypasses
- Authorization or privilege escalation vulnerabilities
- Remote code execution
- SQL injection
- Cross-site scripting (XSS)
- Sensitive data exposure
- Server-side request forgery (SSRF)
- API security vulnerabilities
- Session management flaws
- File upload vulnerabilities
- Vulnerabilities that could materially impact confidentiality, integrity, or availability
4. Severity Classification
Battle Planner may evaluate reports using severity factors such as exploitability, impact, exposure, and user risk.
Critical
- Remote code execution
- Authentication bypass
- Large-scale user data exposure
High
- Privilege escalation across workspaces
- Significant API authorization flaws
- Material access control bypasses
Medium
- Stored XSS
- Limited sensitive information disclosure
Low
- Clickjacking without meaningful impact
- Minor information disclosure
- Missing security headers without demonstrated exploitability
5. Out-of-Scope Reports
The following are generally out of scope or ineligible for rewards unless extraordinary impact is demonstrated:
- Denial-of-service attacks
- Social engineering or phishing
- Physical attacks
- Self-XSS
- Clickjacking without meaningful impact
- Missing SPF/DKIM/DMARC records alone
- Outdated software versions without demonstrated exploitability
- Automated scanner output without clear impact
- Reports affecting third-party systems outside Battle Planner control
- Issues requiring unrealistic user interaction
6. Researcher Expectations
We ask researchers to:
- Avoid intentionally accessing, modifying, or retaining user data
- Avoid disrupting platform availability or reliability
- Avoid destructive testing
- Avoid privacy violations
- Test only against accounts and assets you own or are authorized to access
- Stop testing and report immediately if sensitive user information is exposed
- Keep vulnerability details confidential until remediation is complete
7. Safe Harbor
Battle Planner supports good-faith security research conducted in accordance with this policy. Battle Planner does not intend to pursue legal action against researchers who act in good faith, avoid user harm or service disruption, follow this policy, and provide reasonable time for remediation before disclosure.
This safe harbor does not extend to unlawful activity, privacy violations, extortion attempts, destructive behavior, or actions outside authorized testing boundaries.
8. Submission Requirements
To help us investigate efficiently, reports should include:
- A clear description of the issue
- Reproduction steps
- Proof-of-concept details where appropriate
- Impact explanation
- Relevant screenshots, logs, or technical evidence
- Your contact information
9. Response Process
Battle Planner aims to:
- Acknowledge reports promptly
- Investigate reported issues in a reasonable timeframe
- Communicate material status updates when practical
- Prioritize remediation based on severity and operational risk
Response and remediation timelines may vary depending on complexity, severity, and operational constraints.
10. Rewards & Recognition
At this time, Battle Planner may provide discretionary rewards or recognition for valid, high-quality vulnerability reports. Reward decisions may consider severity and impact, report quality, novelty of findings, and exploitability. Rewards are not guaranteed and may vary based on program maturity and operational considerations.
11. Disclosure Policy
We request that researchers avoid public disclosure until the issue has been remediated or Battle Planner has had a reasonable opportunity to investigate and address it.
12. Report a Vulnerability
Please send vulnerability reports to: security@battleplanner.app