We are committed to protecting our users' data and the integrity of our platform. If you believe you have found a security vulnerability in Two Minute Reports, we want to hear from you — and valid Critical and High severity findings are rewarded.
Last updated: July 16, 2026
We value the work of security researchers and the broader security community. We pledge to investigate every valid report, keep you informed throughout the process, resolve confirmed vulnerabilities promptly, and reward researchers who follow this policy.
Security research conducted in good faith and in accordance with this policy is considered authorized. We will not initiate legal action against you, or ask law enforcement to investigate you, for discovering and reporting vulnerabilities under this program.
Only testing against the assets listed below is authorized under this program. If you are unsure whether something is in scope, ask us first at [email protected].
Web application
https://www.twominutereports.com and all its pages
Owned subdomains
Subdomains fully owned and operated by Two Minute Reports (e.g., hub.twominutereports.com)
Public APIs
Publicly accessible API endpoints operated by Two Minute Reports
Official add-ons
Two Minute Reports apps and add-ons published by us (e.g., our Google Workspace add-on)
At this time, monetary rewards are offered for Critical and High severity vulnerabilities only. Rewards are based on severity, impact, and report quality, and you can choose a cash reward or Two Minute Reports subscription credits at a 1:1 ratio (1 USD = 1 credit-month).
| Severity | Cash Reward | Subscription Credit Alternative | Example Issues |
|---|---|---|---|
| Critical | $50 – $70 | 50 – 70 credit-months | Remote code execution, SQL injection with data access, authentication bypass, cross-tenant data exposure |
| High | $25 – $50 | 25 – 50 credit-months | Stored XSS, privilege escalation, IDOR exposing sensitive data, significant access-control flaws |
| Medium / Low | $10 – $25 | 10 – 25 credit-months | Reflected XSS, CSRF on sensitive actions, IDOR with limited impact, minor information disclosure, security misconfigurations with limited practical impact |
or 50 – 70 credit-months
Remote code execution, SQL injection with data access, authentication bypass, cross-tenant data exposure
or 25 – 50 credit-months
Stored XSS, privilege escalation, IDOR exposing sensitive data, significant access-control flaws
or 10 – 25 credit-months
Reflected XSS, CSRF on sensitive actions, IDOR with limited impact, minor information disclosure, security misconfigurations with limited practical impact
Reward guidelines
Email your report to [email protected]. For critical issues that need immediate attention, include "URGENT" in the subject line. Please include the following in your report:
Vulnerability description
A clear and concise explanation of the issue
Steps to reproduce
Detailed instructions so we can replicate the vulnerability
Proof of Concept
Screenshots, video, or code snippets demonstrating the issue
Impact assessment
Potential consequences and your suggested severity level
Affected URLs / endpoints
The specific locations where the vulnerability was found
Environment details
Browser, operating system, and other relevant details
Acknowledgment
We confirm receipt of your report within 1 business day.
Triage
Our team validates the finding and shares a severity classification and reward estimate within 5 business days.
Remediation
We fix Critical and High severity issues within 30 days, and Medium and Low severity issues within 90 days of acknowledgment.
Reward
Payment is processed within 14 days after the fix is confirmed, via PayPal or as subscription credits — your choice.
We ask that you keep the details of any vulnerability confidential until we have remediated it, or until 90 days have passed since acknowledgment — whichever comes first. We are happy to coordinate on public disclosure once a fix is in place.
With your explicit consent, we are glad to publicly acknowledge your contribution once the issue is resolved. You may also choose to remain anonymous — recognition is always optional and never a condition of receiving a reward.
You must be legally able to receive rewards under the laws of your jurisdiction. Current employees and contractors of Two Minute Reports, and their immediate family members, are not eligible for rewards. You must not be on any sanctions list or located in a country subject to trade restrictions.
Participation in this program constitutes acceptance of these terms. Two Minute Reports reserves the right to modify the scope, rewards, or terms of this program at any time; significant changes will be reflected on this page. Severity classification and final reward amounts are at our sole discretion, and disputes will be resolved through good-faith discussion.
This program does not authorize testing against systems we do not own, and it does not permit any activity that violates applicable law. When in doubt, contact us at [email protected] before testing.
Every report helps keep Two Minute Reports safe for everyone. We read and respond to every submission.
Email [email protected]