ProxyMobile logo
Security

Responsible disclosure & bug bounty policy

If you find a vulnerability in ProxyMobile, we want to hear about it. This page sets out what is in scope, what we pay for, what we do not pay for, and how to report so there are no surprises on either side.

Scope

In scope

  • This website, proxymobile.net
  • The customer dashboard you sign in to, and its API
  • Rotation links, API keys and proxy credential handling inside the dashboard

Out of scope

  • Proxy gateways, modem hosts and the mobile carrier networks behind them
  • Third-party services: payment processors, Telegram, Cloudflare, email providers
  • Marketing assets served from legacy CDN paths
  • Any customer account or data that is not yours

What we pay

Rewards are for demonstrated impact on our systems or our customers. Amounts are in USD.

Critical
$500 – $1,000
  • Remote code execution on our servers
  • SQL injection that reads or writes customer data
  • Authentication bypass into any account without its credentials
  • Payment or balance manipulation — proxies, credit or refunds without paying
  • Bulk exposure of other customers' proxy credentials or personal data
High
$200 – $500
  • Reading or changing another customer's proxies, orders or account details (IDOR)
  • Stored cross-site scripting that runs in another customer's or an admin's session
  • Privilege escalation from a customer account to admin functions
  • Server-side request forgery reaching internal services
  • Theft of another account's API key, rotation link or session
Medium
$50 – $200
  • Cross-site request forgery on an action that changes account state
  • Reflected cross-site scripting that requires the victim to click a link
  • Rate-limit bypass that leads to a demonstrated account takeover
  • Pricing or business-logic errors with a demonstrated financial impact
Low / Informational
$0

Acknowledged and fixed where warranted, but not paid. The full list is below so you can check before you write the report.

What we do not pay for

These are accepted as Low or Informational at most. We will read them and fix what is worth fixing, but no bounty is issued and a Critical or High label on the report does not change that.

Rules of engagement

  1. First valid report wins. Duplicates and reports of issues we already know about are not paid. One payment per root cause, however many endpoints it affects.
  2. Prove it, then stop. Access only your own accounts and data. If a test would expose someone else's data, stop at the first proof and report — do not pivot, download or persist.
  3. Do not degrade the service. No load testing, no automated fuzzing at volume, no tests against proxy gateways, modem hosts or carrier networks. Those are out of scope entirely.
  4. Give us time. Do not publish before we have fixed the issue and 30 days have passed. We will tell you when a fix is live.
  5. Severity is ours to set. We rate impact on our own systems, using the Bugcrowd Vulnerability Rating Taxonomy as the reference. Payment amounts are at our discretion within the ranges above and are paid by PayPal or USDT.
Safe harbour. Research that follows these rules is authorised. We will not pursue legal action against you for good-faith testing within scope, and we ask that you extend the same good faith to us: no extortion, no threats of disclosure, no “pay first, details later”.

How to report

Email support@proxymobile.net with the subject Security report. Include the affected URL, exact steps to reproduce, the account you used, and a proof of concept. We acknowledge within 5 business days and give a severity decision within 10 business days.

Machine-readable contact details are at /.well-known/security.txt.

Send a report

Policy last updated 2026-09-02.