Willed bug bounty programme: historical snapshot This is an archived copy of the former paid programme, not a current reward offer. For the current disclosure policy and transition notice, see: https://www.willed.com.au/security/bug-bounty-program Source: https://www.willed.com.au/security/bug-bounty-program Retrieved: 2026-09-08T01:00:21.185898+10:00 This records the page as retrieved, not proof of its content in 2024. ----- Begin captured policy text ----- BUG BOUNTY PROGRAM Find a flaw, get rewarded. We value the contributions of security researchers in helping us maintain a secure platform for our users. This program rewards individuals who discover and responsibly report vulnerabilities in our systems. THE PROGRAM How to take part. Scope Our bug bounty program covers the following domains and applications: willed.com.au app.willed.com.au API and Firebase-backed workflows reachable from those applications Rewards We offer rewards based on the severity and impact of the reported vulnerabilities: CRITICAL $1,000 – $5,000 HIGH $500 – $1,000 MEDIUM $100 – $500 LOW $50 – $100 Submission guidelines Prepare a detailed report of the vulnerability you’ve discovered. Send your report via email to security@willed.com.au with the subject line ‘Bug Bounty Submission’. In your email, include: A clear description of the vulnerability Detailed steps to reproduce the issue Any relevant screenshots or proof of concept Only the minimum evidence needed to demonstrate impact Your contact information for follow-up communication Rules of engagement Do not attempt to access or modify user data. Avoid denial-of-service attacks. Do not use automated scanning tools without permission. Stop testing and report promptly if you encounter personal information, authentication bypasses, or access to another user’s account. Keep findings confidential until we have investigated and remediated them. Legal We will not initiate legal action or make a complaint to law enforcement for security research conducted in good faith, within the scope of this program, and in accordance with these rules. Safe harbour does not apply to activity that harms availability, accesses, modifies, deletes, or exfiltrates personal information beyond the minimum needed to demonstrate impact, targets third-party systems, uses social engineering or physical attacks, or continues after we ask you to stop. Contact For any questions or concerns, please contact our security team at security@willed.com.au. Acknowledgements We appreciate the efforts of all security researchers who contribute to making our platform more secure. ----- End captured policy text -----