Responsible Disclosure
Last updated: June 6, 2026
Bounty Payouts Paused
Bounty payouts are temporarily paused due to a high volume of incoming submissions. Submissions are still accepted, however reports submitted during this period will not result in a payout until the program has resumed. Effective June 6, 2026 at 11:00 AM MT. Please check back here for status updates.
We deeply appreciate the efforts of independent security researchers in helping us keep our systems and users safe. This document outlines our vulnerability reward matrix, detailing the severity levels, examples of qualifying exploits, and the corresponding payout tiers. The maximum reward for a single vulnerability submission is $1,000 USD.
Program Scope
All vulnerabilities may be reported, but the following conditions must be met to be considered in-scope for a potential monetary payout.
- GitHub Projects: The affected project must be hosted under the github.com/dfpc-coe organization. If the vulnerability exists in a third-party library, it must be demonstrably exploitable via the CloudTAK project and not merely a theoretical exploit in a library that CloudTAK happens to use.
- Production Environments: Any vulnerability found on cotak.gov or any of its subdomains qualifies as in-scope.
Vulnerability Reward Matrix
| Severity | Payout (USD) | Description & Examples |
|---|---|---|
| Critical | $800 - $1,000 | Vulnerabilities that cause a privilege escalation from unprivileged to admin, allow for Remote Code Execution (RCE), result in full system compromise, or enable SQL injection exposing sensitive Personally Identifiable Information (PII) or financial data. |
| High | $300 - $799 | Significant vulnerabilities that compromise data or bypass security controls. Examples include Stored Cross-Site Scripting (XSS), bypassing authentication/authorization for non-admin accounts, demonstrable Server-Side Request Forgery (SSRF), or exposure of non-public user data. |
| Medium | $100 - $299 | Exploits that require user interaction or specific configurations to execute. Examples include Reflected Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF) on sensitive actions, Subdomain Takeover, or misconfigurations leading to limited data exposure. |
| Low | $25 - $99 | Issues that pose a minor security risk or require extremely unlikely circumstances to exploit. Examples include Open Redirects, minor misconfigurations, or informational disclosures (e.g., detailed server version banners, internal IP addresses). |
| Info | $0 (Swag / Hall of Fame) | Non-exploitable bugs that present a theoretical security risk, best-practice suggestions, SSL/TLS configuration issues, or issues explicitly listed as out-of-scope. |
General Program Rules & Conditions
- Assessment: The CloudTAK team reserves the right to determine whether a reported vulnerability is in-scope, and to determine if and how much a payout is made. Payout decisions are based on the true impact, exploitability, and complexity of the reported vulnerability.
- First to Report: To qualify for a reward, you must be the first researcher to report the specific vulnerability. Duplicate reports will not be rewarded.
- Confidentiality: Vulnerabilities must be reported securely and confidentially. Public disclosure before remediation will disqualify you from receiving a bounty.
- Prohibited Actions: Social engineering (including phishing), physical attacks against our employees or infrastructure, and automated scanning using disruptive tools are strictly prohibited and ineligible for rewards.
- Out of Scope: Denial of Service (DoS/DDoS) attacks, brute-force attacks, and spam are strictly out of scope.
Reporting
Vulnerabilities can be submitted through either of the following channels:
- Email: Send a detailed report to support@cotak.gov. Please include steps to reproduce, potential impact, and any supporting evidence.
- GitHub Private Vulnerability Reporting: Submit directly through GitHub's private vulnerability reporting feature on the relevant repository. See GitHub's documentation for instructions.