We are committed to protecting our users' data and the integrity of our platform. If you believe you have found a security vulnerability in Two Minute Reports, we want to hear from you. Valid findings are rewarded based on severity and impact.
Last updated: July 16, 2026
We value the work of security researchers and the broader security community. We pledge to investigate every valid report, keep you informed throughout the process, resolve confirmed vulnerabilities promptly, and reward researchers who follow this policy.
Security research conducted in good faith and in accordance with this policy is considered authorized. We will not initiate legal action against you, or ask law enforcement to investigate you, for discovering and reporting vulnerabilities under this program.
Only testing against the assets listed below is authorized under this program. If you are unsure whether something is in scope, ask us first at [email protected].
Web application
https://www.twominutereports.com and all its pages
Owned subdomains
Subdomains fully owned and operated by Two Minute Reports (e.g., hub.twominutereports.com)
Public APIs
Publicly accessible API endpoints operated by Two Minute Reports
Official add-ons
Two Minute Reports apps and add-ons published by us (e.g., our Google Workspace add-on)
Up to $100 for critical vulnerabilities
Reward guidelines
Email your report to [email protected]. For critical issues that need immediate attention, include "URGENT" in the subject line. Please include the following in your report:
Vulnerability description
A clear and concise explanation of the issue
Steps to reproduce
Detailed instructions so we can replicate the vulnerability
Proof of Concept
Screenshots, video, or code snippets demonstrating the issue
Impact assessment
Potential consequences and your suggested severity level
Affected URLs / endpoints
The specific locations where the vulnerability was found
Environment details
Browser, operating system, and other relevant details
This program is intended for responsible security researchers conducting good-faith testing. Researchers who engage in any of the following activities will be banned from the program permanently:
Violations will result in immediate and permanent suspension from the bug bounty program, forfeiture of any pending rewards, and potential legal action.
We ask that you keep the details of any vulnerability confidential until we have remediated it, or until 90 days have passed since acknowledgment — whichever comes first. We are happy to coordinate on public disclosure once a fix is in place.
With your explicit consent, we are glad to publicly acknowledge your contribution once the issue is resolved. You may also choose to remain anonymous — recognition is always optional and never a condition of receiving a reward.
You must be legally able to receive rewards under the laws of your jurisdiction. Current employees and contractors of Two Minute Reports, and their immediate family members, are not eligible for rewards. You must not be on any sanctions list or located in a country subject to trade restrictions.
Participation in this program constitutes acceptance of these terms. Two Minute Reports reserves the right to modify the scope, rewards, or terms of this program at any time; significant changes will be reflected on this page. Severity classification and final reward amounts are at our sole discretion, and disputes will be resolved through good-faith discussion.
Third-Party Service Integration Scope: Vulnerability testing must focus strictly on Two Minute Reports' assets and API endpoints. Security testing directly against third-party integrated services (such as Google Ads API, Google Sheets, Meta Graph API, or Amazon Web Services) is strictly prohibited under this program and must be reported directly to those respective platforms.
This program does not authorize testing against systems we do not own, and it does not permit any activity that violates applicable law. When in doubt, contact us at [email protected] before testing.
Every report helps keep Two Minute Reports safe for everyone. We read and respond to every submission.
Email [email protected]