Responsible disclosure & bug bounty policy
If HourlyProxies has a vulnerability and you find it, we would like to know. So that neither of us is surprised, this page covers scope, what we pay for, what we don't pay for and how to report.
Scope
In scope
- This website,
hourlyproxies.com - The customer dashboard where you sign in, and the API it exposes
- The way rotation links, API keys and proxy credentials are managed in the dashboard
Out of scope
- Proxy gateways and modem hosts, together with the mobile carrier networks behind them
- Services from third parties, including payment processors, Telegram, Cloudflare and email providers
- Marketing assets served from legacy CDN paths
- Customer accounts and data except your own
What we pay
You are rewarded for impact on our systems or customers that you have demonstrated. Amounts are in USD.
- Remote code execution on our servers
- SQL injection that lets you read or write customer data
- Bypassing login to get into any account without having its credentials
- Manipulating a payment or balance so proxies, credit or refunds come without paying
- Large-scale exposure of other customers' proxy credentials or personal data
- Seeing or changing the proxies, orders or account details of another customer (IDOR)
- Stored cross-site scripting that runs inside the session of another customer or of an admin
- Escalating a customer account's privileges to reach admin functions
- Server-side request forgery reaching internal services
- Another account's API key, rotation link or session being stolen
- Cross-site request forgery on any action that modifies account state
- Reflected cross-site scripting where the victim has to click a link
- Bypassing rate limits when it leads to a demonstrated account takeover
- Pricing or business-logic errors where a financial impact is demonstrated
They are acknowledged and fixed where warranted, but unpaid. The whole list sits below, so you can check it before you write a report.
Rules of engagement
- First valid report wins. A duplicate, or a report of an issue we already know about, is not paid. You are paid once for each root cause, whatever number of endpoints it affects.
- Prove it, then stop. Access only your own accounts and data. If a test would expose another person's data, end it at the first proof and report, without pivoting, downloading or persisting.
- Do not degrade the service. Load testing, automated fuzzing in volume, and testing proxy gateways, modem hosts or carrier networks are not permitted. Those are out of scope entirely.
- Give us time. Do not go public until the issue is fixed and 30 days have run. When a fix goes live, we let you know.
- Severity is ours to set. The Bugcrowd Vulnerability Rating Taxonomy is our reference when we rate impact on our own systems. The amount paid is at our discretion within the ranges above, and payment is by PayPal or USDT.
What we do not pay for
These count as Low or Informational at the very most. They will be read and anything worth fixing will be fixed, but no bounty is issued, and a Critical or High label on the report has no effect on that.
- Old sessions that keep running after a logout, password change or password reset until the session token times out
- A missing or “weak” security header (CSP, HSTS, X-Frame-Options, Referrer-Policy) reported without a working exploit
- Clickjacking where the page has no sensitive action to trigger
- Cookie attributes, where the cookie is not a session cookie
- Email or username enumeration, also when done through timing or error messages
- Forgot-password, login or rate-limit observations if no account takeover has been demonstrated
- Password policy opinions about length, complexity, common-password lists, or not forcing rotation
- Accounts without two-factor authentication, or with 2FA optional
- Self-XSS, or XSS that works only when attackers run it in their own session
- CSRF on the login, logout or language form, or another non-sensitive one
- Open redirects unless they leak a token or credential
- Disclosed software versions, server banners, stack traces or paths when no sensitive data is included
- SPF, DKIM or DMARC configuration reports
- Automated scanner findings unless a proof of concept comes with them
- Load-generating tests of any kind, including denial of service, resource exhaustion and brute force
- Social engineering or phishing directed at our staff or customers, as well as physical attacks
- Issues found in outside services we use, for example payment processors, Telegram, Cloudflare and email providers
- Out-of-date library versions where no working exploit against our deployment exists
- Any attack that only works with a man-in-the-middle position, a compromised device or a rooted phone
- Best-practice notes, risks that exist only in theory, and duplicates of known issues
How to report
Email [email protected] with the subject Security report. Put in the affected URL, exact steps that reproduce it, the account you used, and a proof of concept. Our clock: acknowledgment within 5 business days, severity decision within 10 business days.
Machine-readable contact details are at /.well-known/security.txt.
Send a reportPolicy last updated 2026-10-10.
