Bug Bounty Program
Security is core to everything we do at wservices. We invite security researchers to responsibly discover and report vulnerabilities in our infrastructure and web interface (wcenter). Verified, previously-unknown reports are rewarded.
Scope
In scope
- wservices.ch and its public web services
- The wcenter control panel
- djangoeurope.com hosting infrastructure
- Our mail and DNS services
Out of scope
- Third-party services and sub-processors
- Social engineering and phishing of our staff or customers
- Physical attacks against data centers or offices
- Denial-of-service (DoS/DDoS) and volumetric attacks
- Automated scanner output without a working proof-of-concept
The Process
- 1
Registration
Register your intent by e-mailing security@wservices.ch with your name or handle and a short description of your research focus. You receive a confirmation and a reporting reference.
- 2
Testing
Test only in-scope targets. Never access, modify or destroy data that is not yours. Use a dedicated test account where possible. No DoS, no spam, no automated mass-scanning.
- 3
Delivery (Report Submission)
Submit a detailed report to security@wservices.ch including the affected target/URL, vulnerability type, step-by-step reproduction, a working proof-of-concept, an impact assessment and any suggested remediation. Encrypt sensitive reports with our PGP key on request.
- 4
Triage & Validation
We acknowledge your report within 3 business days and validate it. We may contact you for clarification during this phase.
- 5
Resolution
We fix confirmed issues and keep you updated on the progress. Please allow reasonable time for remediation before any public disclosure (coordinated disclosure, 90 days recommended).
- 6
Reward
Once the issue is fixed and verified, we grant the applicable reward (see below).
Rewards
Rewards are granted at wservices’ discretion based on severity, impact and report quality. Duplicates are awarded to the first reporter only.
| Severity / Finding | Reward |
|---|---|
| Valid report (Hall of Fame) | Public recognition on our Security Hall of Fame for every valid, previously-unknown report. |
| Low / Medium severity | One year of a free Starter, Growth or Business plan (depending on severity/impact), or a free djangoeurope hosting plan for one year. |
| High severity | A free djangoeurope hosting plan for one year, plus Hall of Fame. |
| Critical — Remote Code Execution as root (root RCE) | Top reward of $500, plus Hall of Fame and a free hosting plan. |
Rules & Safe Harbor
- Follow responsible, coordinated disclosure; do not publicly disclose a finding before we have resolved it and agreed on disclosure.
- Do not violate the privacy of our users, degrade our services, or destroy data.
- Comply with Swiss law and these program rules at all times.
- Good-faith security research conducted under these rules will not lead to legal action from wservices.