Security at Two Minute Reports

Bug Bounty & Vulnerability Disclosure Program

We are committed to protecting our users' data and the integrity of our platform. If you believe you have found a security vulnerability in Two Minute Reports, we want to hear from you. Valid findings are rewarded based on severity and impact.

Last updated: July 16, 2026

Our Commitment

We value the work of security researchers and the broader security community. We pledge to investigate every valid report, keep you informed throughout the process, resolve confirmed vulnerabilities promptly, and reward researchers who follow this policy.

Safe Harbor

Security research conducted in good faith and in accordance with this policy is considered authorized. We will not initiate legal action against you, or ask law enforcement to investigate you, for discovering and reporting vulnerabilities under this program.

Program Scope

Only testing against the assets listed below is authorized under this program. If you are unsure whether something is in scope, ask us first at [email protected].

In Scope

  • Web application

    https://www.twominutereports.com and all its pages

  • Owned subdomains

    Subdomains fully owned and operated by Two Minute Reports (e.g., hub.twominutereports.com)

  • Public APIs

    Publicly accessible API endpoints operated by Two Minute Reports

  • Official add-ons

    Two Minute Reports apps and add-ons published by us (e.g., our Google Workspace add-on)

Out of Scope

  • Social engineering (phishing, vishing) of our employees, contractors, or users
  • Denial of Service (DoS/DDoS) or resource-exhaustion attacks
  • Bulk automated vulnerability scanning that generates high volumes of traffic
  • Third-party applications or services not owned or managed by Two Minute Reports
  • Testing against production accounts that are not your own
  • Missing security headers or best-practice flags without a demonstrable exploit
  • Email spoofing findings (SPF/DKIM/DMARC) without a working proof of concept
  • Self-XSS or issues requiring unlikely user interaction
  • Clickjacking on pages with no sensitive actions
  • Basic or informational findings without demonstrated security impact (e.g., software version disclosure, verbose error messages, descriptive stack traces)
  • Duplicate reports of issues already reported by another researcher or known to us
  • Findings from automated scanners without manual validation

Rewards for valid security findings

Up to $100 for critical vulnerabilities

Reward guidelines

  • Report quality matters: Poor reproduction steps, lack of proof of concept, or vague impact assessments will delay or reduce rewards. High-quality, well-documented reports are prioritized.
  • Critical severity vulnerabilities are the primary focus for monetary rewards. Other findings will be investigated, and rewards may be considered based on severity, impact, and quality. All valid reports are welcome under our Vulnerability Disclosure Policy and will be triaged and fixed.
  • Final classification and reward eligibility are at the sole discretion of Two Minute Reports. We reserve the right to deny payment for findings deemed trivial, already known, or of negligible impact.
  • Duplicate reports: if the same vulnerability is reported by more than one researcher, only the first complete, reproducible report we receive is eligible for a reward (based on the time the report arrives in our inbox). Later reports of the same issue are marked as duplicates and are not eligible, though we will let you know the issue was already reported.
  • Subscription credits can be applied to your own account or gifted to another account.
  • Out-of-scope submissions and reports submitted by researchers previously suspended for abuse are not eligible for rewards.

How to Report a Vulnerability

Email your report to [email protected]. For critical issues that need immediate attention, include "URGENT" in the subject line. Please include the following in your report:

1

Vulnerability description

A clear and concise explanation of the issue

2

Steps to reproduce

Detailed instructions so we can replicate the vulnerability

3

Proof of Concept

Screenshots, video, or code snippets demonstrating the issue

4

Impact assessment

Potential consequences and your suggested severity level

5

Affected URLs / endpoints

The specific locations where the vulnerability was found

6

Environment details

Browser, operating system, and other relevant details

Rules of Engagement

Please Do

  • Only interact with accounts and test data you own
  • Report vulnerabilities as soon as possible after discovery
  • Provide clear, detailed reports with reproduction steps
  • Give us reasonable time to fix issues before any public disclosure (minimum 90 days)
  • Comply with all applicable laws and regulations

Please Don't

  • Access, modify, or destroy data belonging to other users
  • Publicly disclose a vulnerability before we have addressed it
  • Perform testing that could degrade or disrupt our services
  • Exploit a vulnerability beyond what is needed to demonstrate it
  • Demand payment before disclosing the details of a finding
  • Conduct continuous, aggressive, or high-volume testing attacks
  • Create multiple test accounts or attempt account enumeration
  • Insert, modify, or delete data in our databases (even test data)
  • Engage in activities that spam our security team with low-quality or duplicate reports

Abuse Prevention & Program Suspension

This program is intended for responsible security researchers conducting good-faith testing. Researchers who engage in any of the following activities will be banned from the program permanently:

  • Continuous or aggressive testing: Repeatedly scanning, attacking, or probing our infrastructure without prior coordination, or sending high-volume requests that disrupt service
  • Unauthorized account creation: Creating multiple test accounts, enumeration attempts, or account abuse under the premise of security research
  • Data manipulation: Inserting, modifying, or deleting data in our production or test databases without explicit authorization from our security team
  • Spam or low-quality reports: Submitting numerous trivial, duplicate, or low-effort reports to inflate submission counts or attempt to claim rewards
  • Extortion or threats: Threatening to publicly disclose vulnerabilities, demand payment, or cause harm to our service or reputation

Violations will result in immediate and permanent suspension from the bug bounty program, forfeiture of any pending rewards, and potential legal action.

Coordinated Disclosure

We ask that you keep the details of any vulnerability confidential until we have remediated it, or until 90 days have passed since acknowledgment — whichever comes first. We are happy to coordinate on public disclosure once a fix is in place.

Recognition

With your explicit consent, we are glad to publicly acknowledge your contribution once the issue is resolved. You may also choose to remain anonymous — recognition is always optional and never a condition of receiving a reward.

Eligibility

You must be legally able to receive rewards under the laws of your jurisdiction. Current employees and contractors of Two Minute Reports, and their immediate family members, are not eligible for rewards. You must not be on any sanctions list or located in a country subject to trade restrictions.

Program Terms

Participation in this program constitutes acceptance of these terms. Two Minute Reports reserves the right to modify the scope, rewards, or terms of this program at any time; significant changes will be reflected on this page. Severity classification and final reward amounts are at our sole discretion, and disputes will be resolved through good-faith discussion.

Third-Party Service Integration Scope: Vulnerability testing must focus strictly on Two Minute Reports' assets and API endpoints. Security testing directly against third-party integrated services (such as Google Ads API, Google Sheets, Meta Graph API, or Amazon Web Services) is strictly prohibited under this program and must be reported directly to those respective platforms.

This program does not authorize testing against systems we do not own, and it does not permit any activity that violates applicable law. When in doubt, contact us at [email protected] before testing.

Found something? Let us know.

Every report helps keep Two Minute Reports safe for everyone. We read and respond to every submission.

Email [email protected]