Security Bounty & Vulnerability Disclosure Policy
Last updated: June 30, 2026
Euronodes Ltd takes the security of our infrastructure and our customers seriously. We welcome reports from security researchers acting in good faith, and we recognise validated, original findings.
This is our security bounty and responsible-disclosure policy. It explains what is in scope, how to test responsibly (penetration testing / pentest), what we will and will not reward, and the legal protections we extend to researchers who follow it. For non-security functional bugs (something in the portal or website misbehaving), see our Bug Bounty instead.
If you believe you have found a security issue, please read this page in full before testing or reporting.
Scope
The following assets are in scope for testing under this policy:
euronodes.comandwww.euronodes.comkb.euronodes.comninja.euronodes.com(billing portal)my.euronodes.com(customer portal)eu-west-1.euronodes.com(Silo S3, currently in beta)- The Euronodes customer panel and its public API endpoints
- Our published nameservers and DNS configuration for the above domains
If you are unsure whether a specific asset is in scope, ask first at the reporting address below before testing.
Out of scope
The following are explicitly out of scope. Testing them is not authorised under this policy and is not eligible for reward:
- Customer virtual machines, services, and data. The VMs and services our customers run on our infrastructure are their property and their responsibility, not ours (see our VPS/VM security model). You must not test, access, scan, or interact with any customer VM, IP, or service. This is a hard line.
- Any third-party service, vendor, or upstream provider (including our datacenter, transit, and CDN partners)
- Our physical facilities and the facilities of our datacenter partners in Lisbon and Prague
- Staff, contractors, and customers as targets of social engineering
- Internal-only systems not reachable from the public internet
Rules of engagement
Good-faith testing under this policy means all of the following:
- Test only assets listed in scope, using your own test account where authentication is required
- Stop at proof of concept. Demonstrate the vulnerability, do not exploit it further
- Do not access, modify, download, or exfiltrate any data that is not your own. If you encounter customer data, personal data, or credentials, stop immediately and report it without retaining a copy
- No denial of service, resource exhaustion, or load testing of any kind
- No automated scanning or fuzzing that degrades or risks degrading service for others
- No spam, no mass account creation, no brute forcing of credentials
- Do not publicly disclose any finding before we have confirmed it is resolved and agreed timing with you
- One issue per report, with enough detail for us to reproduce it
If you cannot demonstrate an issue without breaking one of these rules, contact us first and we will work out a safe way to validate it.
Vulnerabilities we do not reward
The following are generally not eligible for reward unless you can demonstrate a concrete, exploitable security impact. We are happy to receive them as informational reports, but they do not qualify on their own:
- Missing or misconfigured SPF, DKIM, or DMARC records
- Missing security headers (CSP, HSTS, X-Frame-Options, and similar) without a demonstrated exploit
- Clickjacking on pages with no sensitive action
- Self-XSS, or issues requiring a victim to paste attacker-supplied content into their own console
- Software version disclosure or banner grabbing without a working exploit
- Outdated library or software versions without a demonstrated vulnerability
- TLS/SSL configuration findings (cipher suites, protocol versions) without a working attack
- Open redirects without demonstrated impact
- Rate limiting or lack of brute-force protection without demonstrated account compromise
- Reports generated solely by automated scanners, without manual validation
- Findings affecting out-of-scope assets
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will:
- Consider your testing authorised under this policy
- Not pursue or support legal action against you for that testing
- Work with you to understand and resolve the issue
This safe harbor applies only to testing that stays within scope and within the rules of engagement above. Activity that falls outside this policy, in particular anything touching customer VMs or data, denial of service, or data exfiltration, is not authorised and is not protected.
If legal action is initiated against you by a third party for activity that complied with this policy, we will make it known that your actions were conducted under this policy.
Rewards
We reward original, validated findings. Rewards are determined by us based on the severity and real-world impact of the issue, using a CVSS-informed assessment.
| Severity | Reward |
|---|---|
| Critical | EUR 200 to 400 |
| High | EUR 100 |
| Medium | EUR 50 |
| Low | EUR 20 |
| Informational | Public acknowledgement |
Every paid reward (Low and above) can be taken as cash or account credit, whichever you prefer - we confirm which with you on validation. Informational findings are recognised with public credit on our acknowledgements page.
Reward conditions:
- Rewards are paid per unique, validated finding
- The vulnerability must be live and reproducible on our current production systems on the day it is reported. Already-fixed issues, and findings that only affect an outdated, cached, or archived version, are not eligible
- The first person to report a given issue is the one eligible. Duplicates are not rewarded
- We determine severity, validity, and whether two reports are duplicates
- Payment follows confirmation of the finding and, where applicable, deployment of a fix
- Findings on out-of-scope assets, and the issue classes listed above, are not eligible
- Rewards are issued per the table above, as cash or account credit at your choice (not credit only) - we confirm the form with you on validation
With your permission, we will credit you by name or handle on our security acknowledgements page.
How to report
Send your report to [email protected] with Security in the subject line.
Please include:
- The affected asset (domain, endpoint, or IP)
- The vulnerability class
- Clear, step-by-step reproduction instructions or a proof of concept
- The impact you believe the issue has
- Any supporting material (requests, responses, screenshots)
The more precisely we can reproduce the issue, the faster we can validate and reward it.
Reporting abuse or illegal content is a different channel
This policy is for security vulnerabilities. To report abuse, illegal activity, or Terms of Service violations by a customer, use [email protected] or the report form instead.
Our commitment
When you report in line with this policy, we will:
- Acknowledge your report within 5 business days
- Give you an initial assessment of validity and severity within 10 business days
- Keep you updated as we work toward a fix
- Credit you, with your permission, once the issue is resolved
- Issue any applicable reward after the finding is confirmed
We ask that you give us reasonable time to resolve an issue before any public disclosure, and that you coordinate timing with us.
Euronodes Ltd, Reg. HE353288, Limassol, Cyprus. This policy may be updated. Testing conducted under a previous version remains covered by the version in effect at the time of testing.
Euronodes Ltd Agiou Andreou 302, KERMIA CRT OFFICE A, 3035 Limassol, Cyprus [email protected] ยท https://euronodes.com