Kobana
Bug Bounty Program

White Hat Policy

We value security researchers who help us keep our platform secure. Report vulnerabilities responsibly and get rewarded.

Last updated: September 5, 2026

Our Commitment

Kobana encourages security researchers to report vulnerabilities responsibly. We investigate all legitimate reports and commit to remedying identified issues.

We will not take legal action against researchers who follow the responsible disclosure guidelines described in this policy.

Responsible Disclosure Policy

To receive legal protection, researchers must follow these guidelines

Allow reasonable time for investigation before publicly disclosing or sharing vulnerability details

Obtain authorization before accessing individual accounts or customer data

Minimize damage to other customers by avoiding data destruction or service interruption

Do not exploit discovered vulnerabilities for any purpose

Comply with all applicable laws and regulations

Rewards Program

Reward Structure

Different ranges depending on whether the report demonstrates real or only potential harm

Real harm

Material impact demonstrated within the responsible disclosure policy — for example, real personal data exposed, a valid production token reused, an account compromised or an end-to-end exploit chain reproduced in production.

Potential harm

Reproducible vector and correct technical analysis, but no material impact realized — for example, tests with synthetic data, metadata without PII or a chain that depends on an additional unverified assumption.

Vulnerability TypeReal harmPotential harm

Non-security related bugs

Functional issues without security impact

Not applicableNot applicable

Private data not protected by LGPD

Exposure of private data outside LGPD scope

US$ 100 - US$ 200US$ 50 - US$ 100

Access to LGPD protected data

Vulnerabilities that allow access to personal data

US$ 200 - US$ 1,000US$ 100 - US$ 500

Access to all Kobana data

Critical full access vulnerabilities

US$ 1,000+US$ 500+

Ex-gratia reward

For real findings with low exploitability or outside the financial ranges above, we may pay an ex-gratia reward starting at US$ 50 as recognition of the contribution, without setting a precedent for future cases.

Charity donations

Donations to charities or NGOs (subject to Kobana approval) receive double rewards. The invoice must be sent within 10 days after approval for payment processing.

Program Scope

Covered Assets

Any subdomain of the domains below, including production and sandbox environments

Primary domain

*.kobana.com.br

Boleto hosting

*.bole.to

Document hosting

*.kdoc.to

Third-party services are not covered by the program.

Ineligible Reports

The following types of reports are not eligible for reward

Social engineering, spam or DDoS attacks

Content insertion, except if demonstrating considerable risk

Sending messages to anyone at Kobana

Vulnerabilities in third-party integrations

Scripts on sandbox domains

Vulnerabilities requiring physical access to user device

Vulnerabilities in outdated software not in use

Duplicate reports, under the root-cause criterion

Reports submitted in collusion, or by someone holding more than one registration

Vulnerabilities introduced or caused by the researcher

Program Integrity

Duplicates, Identity and Good Faith

Rules that ensure each bounty goes to whoever actually found it first

Duplicate reports

We treat as a duplicate any report arising from the same root cause as an earlier one — even if described with different wording, attack vectors, endpoints or proofs of concept. The criterion is the root cause, not the symptom, screen or endpoint affected.

  • A report is also a duplicate when the vulnerability had already been identified internally, or was already undergoing remediation, on the date we received it
  • Precedence is set by the date and time of receipt at whitehat@kobana.com.br, as recorded by our e-mail servers — which prevails over any other evidence of precedence
  • We pay a single bounty per root cause, even when the same finding is reported by several people
  • We are not obliged to share the technical details, date or identity of the earlier report with whoever came second
  • At our discretion, and without setting a precedent, we may grant a reduced bounty to a duplicate report that adds materially relevant information to the fix
Single registration and identity verification (KYC)

Each researcher takes part under a single registration. Before paying any bounty, regardless of the amount — including ex-gratia bounties and charitable destinations — we run an identity verification (KYC).

  • Holding or operating more than one registration is not allowed, directly or indirectly, through an intermediary, pseudonym, additional handle, alternative e-mail address or legal entity under your control
  • We ask for an official photo ID, proof of address issued within the last 90 days, and a selfie holding the document, with face and document fully visible in the same image
  • Researchers acting as a legal entity also provide the articles of association or bylaws and proof of CNPJ enrollment, or an equivalent registration abroad
  • The bank or PayPal account designated for payment must be held by the researcher or by the legal entity they indicated
  • We may require a video liveness check, with presentation of the document and gestures requested in real time
  • KYC is performed once per registration, may be requested as early as enrollment, and is repeated if we find a discrepancy or an indication of duplicate registration
  • Refusal suspends payment until cured; after 90 calendar days from the request without compliance, the bounty is forfeited
Good faith and fraud

The program is built on mutual trust. The following are acts of bad faith or fraud against the program, among others:

  • Making a false representation, or presenting an identification, corporate, tax or banking document that is false, altered, belonging to a third party or inconsistent
  • Holding or operating more than one registration in the program, directly or through an intermediary
  • Arranging with others to submit the same finding, or findings from the same root cause, through more than one researcher in order to obtain more than one bounty
  • Presenting as your own a report authored by a third party, or deliberately splitting a single finding into several reports
  • Fabricating, altering or simulating evidence, proofs of concept, logs, requests or screenshots
  • Misleading Kobana as to the severity, impact, scope or originality of the report
  • Reporting a vulnerability that the researcher introduced or caused in our systems
  • Conditioning the disclosure of information upon payment of an amount higher than the one offered, or threatening disclosure as a means of obtaining an advantage

Before any decision, we notify the researcher describing the facts found and allow 10 calendar days for clarifications. Once the conduct is confirmed: forfeiture of pending bounties, refund of amounts received, definitive exclusion from the program and disqualification from re-registering, loss of the safe harbor, notification to the competent authorities, and a non-compensatory penalty in the greater of 2× the bounty claimed and BRL 20,000 (USD 4,000 for foreign tax residents).

How to Report a Vulnerability

Send security reports exclusively to the email below. Do not contact employees directly.

whitehat@kobana.com.br

Guidelines for a good report:

  • Detail reproduction steps with URLs and user IDs
  • Provide clear descriptions of the account used
  • Prioritize clarity over quantity of information
  • Videos should be short, readable (480p+), with written descriptions
  • Include the potential impact of the vulnerability
  • Do not share details with third parties before the fix

Eligibility Requirements

To be eligible, you must:

  • Comply with the responsible disclosure policy
  • Report real security bugs that create privacy/security risks
  • Focus on products within the program scope
  • Exclude ineligible vulnerability types
  • Maintain a single registration in the program and act in good faith
  • Complete identity verification (KYC), regardless of the amount

Payment process:

  • Report validation by the security team
  • Duplicate check under the root-cause criterion
  • Severity classification and reward definition
  • Identity verification (KYC), required for any amount
  • Invoice submission within 10 days after approval
  • Payment processing after invoice receipt

Related Documents

Found a vulnerability?

Report responsibly and help keep Kobana secure for everyone.