Security at Two Minute Reports

Bug Bounty & Vulnerability Disclosure Program

We are committed to protecting our users' data and the integrity of our platform. If you believe you have found a security vulnerability in Two Minute Reports, we want to hear from you — and valid Critical and High severity findings are rewarded.

Last updated: July 16, 2026

Our Commitment

We value the work of security researchers and the broader security community. We pledge to investigate every valid report, keep you informed throughout the process, resolve confirmed vulnerabilities promptly, and reward researchers who follow this policy.

Safe Harbor

Security research conducted in good faith and in accordance with this policy is considered authorized. We will not initiate legal action against you, or ask law enforcement to investigate you, for discovering and reporting vulnerabilities under this program.

Program Scope

Only testing against the assets listed below is authorized under this program. If you are unsure whether something is in scope, ask us first at [email protected].

In Scope

  • Web application

    https://www.twominutereports.com and all its pages

  • Owned subdomains

    Subdomains fully owned and operated by Two Minute Reports (e.g., hub.twominutereports.com)

  • Public APIs

    Publicly accessible API endpoints operated by Two Minute Reports

  • Official add-ons

    Two Minute Reports apps and add-ons published by us (e.g., our Google Workspace add-on)

Out of Scope

  • Social engineering (phishing, vishing) of our employees, contractors, or users
  • Denial of Service (DoS/DDoS) or resource-exhaustion attacks
  • Bulk automated vulnerability scanning that generates high volumes of traffic
  • Third-party applications or services not owned or managed by Two Minute Reports
  • Testing against production accounts that are not your own
  • Missing security headers or best-practice flags without a demonstrable exploit
  • Email spoofing findings (SPF/DKIM/DMARC) without a working proof of concept
  • Self-XSS or issues requiring unlikely user interaction
  • Clickjacking on pages with no sensitive actions
  • Basic or informational findings without demonstrated security impact (e.g., software version disclosure, verbose error messages, descriptive stack traces)
  • Duplicate reports of issues already reported by another researcher or known to us
  • Findings from automated scanners without manual validation

Reward Structure

At this time, monetary rewards are offered for Critical and High severity vulnerabilities only. Rewards are based on severity, impact, and report quality, and you can choose a cash reward or Two Minute Reports subscription credits at a 1:1 ratio (1 USD = 1 credit-month).

Critical$50 – $70

or 50 – 70 credit-months

Remote code execution, SQL injection with data access, authentication bypass, cross-tenant data exposure

High$25 – $50

or 25 – 50 credit-months

Stored XSS, privilege escalation, IDOR exposing sensitive data, significant access-control flaws

Medium / Low$10 – $25

or 10 – 25 credit-months

Reflected XSS, CSRF on sensitive actions, IDOR with limited impact, minor information disclosure, security misconfigurations with limited practical impact

Reward guidelines

  • Severity is assessed using industry standards (CVSS) as a guideline; the final classification and reward amount are at the sole discretion of Two Minute Reports.
  • Medium and Low severity issues, and basic or informational findings, are not eligible for monetary rewards. We still welcome these reports under our Vulnerability Disclosure Policy — they will be triaged and fixed, and may receive public recognition.
  • Duplicate reports: if the same vulnerability is reported by more than one researcher, only the first complete, reproducible report we receive is eligible for a reward (based on the time the report arrives in our inbox). Later reports of the same issue are marked as duplicates and are not eligible, though we will let you know the issue was already reported.
  • Subscription credits can be applied to your own account or gifted to another account.
  • Out-of-scope submissions are not eligible for rewards.

How to Report a Vulnerability

Email your report to [email protected]. For critical issues that need immediate attention, include "URGENT" in the subject line. Please include the following in your report:

1

Vulnerability description

A clear and concise explanation of the issue

2

Steps to reproduce

Detailed instructions so we can replicate the vulnerability

3

Proof of Concept

Screenshots, video, or code snippets demonstrating the issue

4

Impact assessment

Potential consequences and your suggested severity level

5

Affected URLs / endpoints

The specific locations where the vulnerability was found

6

Environment details

Browser, operating system, and other relevant details

What Happens After You Report

1

Acknowledgment

We confirm receipt of your report within 1 business day.

2

Triage

Our team validates the finding and shares a severity classification and reward estimate within 5 business days.

3

Remediation

We fix Critical and High severity issues within 30 days, and Medium and Low severity issues within 90 days of acknowledgment.

4

Reward

Payment is processed within 14 days after the fix is confirmed, via PayPal or as subscription credits — your choice.

Rules of Engagement

Please Do

  • Only interact with accounts and test data you own
  • Report vulnerabilities as soon as possible after discovery
  • Provide clear, detailed reports with reproduction steps
  • Give us reasonable time to fix issues before any public disclosure (minimum 90 days)
  • Comply with all applicable laws and regulations

Please Don't

  • Access, modify, or destroy data belonging to other users
  • Publicly disclose a vulnerability before we have addressed it
  • Perform testing that could degrade or disrupt our services
  • Exploit a vulnerability beyond what is needed to demonstrate it
  • Demand payment before disclosing the details of a finding

Coordinated Disclosure

We ask that you keep the details of any vulnerability confidential until we have remediated it, or until 90 days have passed since acknowledgment — whichever comes first. We are happy to coordinate on public disclosure once a fix is in place.

Recognition

With your explicit consent, we are glad to publicly acknowledge your contribution once the issue is resolved. You may also choose to remain anonymous — recognition is always optional and never a condition of receiving a reward.

Eligibility

You must be legally able to receive rewards under the laws of your jurisdiction. Current employees and contractors of Two Minute Reports, and their immediate family members, are not eligible for rewards. You must not be on any sanctions list or located in a country subject to trade restrictions.

Program Terms

Participation in this program constitutes acceptance of these terms. Two Minute Reports reserves the right to modify the scope, rewards, or terms of this program at any time; significant changes will be reflected on this page. Severity classification and final reward amounts are at our sole discretion, and disputes will be resolved through good-faith discussion.

This program does not authorize testing against systems we do not own, and it does not permit any activity that violates applicable law. When in doubt, contact us at [email protected] before testing.

Found something? Let us know.

Every report helps keep Two Minute Reports safe for everyone. We read and respond to every submission.

Email [email protected]