Bounties
Isolate and report potential security issues
Provide a reproducible report for review.
Reward eligibility is assessed case by case.
Conditions
1. Find a bug
Get to the bottom of an issue you found in the code. Locate the root cause and record the way to replicate the issue.
2. Report a bug
Once documented, send us an email to bounties@gateway.fm with a short description of the issue located and a link to the document.
3. Eligibility review
Confirmed issues are routed to the relevant team. Reward eligibility and amount depend on severity, report quality, duplication, scope, and the current program criteria.
FAQ
Confirmed issues are routed to the relevant team. Reward eligibility and amount depend on severity, report quality, duplication, scope, and the current program criteria.
Severity review may reference Google's published guidance, alongside Gateway's current scope and review criteria.
Duplicate reports are reviewed under the current program criteria; the first valid report may receive priority.
The timeframe varies based on our team's workload and the bug's severity.