GamsGo Security
GamsGo Bug Bounty Program
The GamsGo Bug Bounty Program is designed for external security researchers who want to help protect GamsGo products and users.
Found a vulnerability with real security impact? Submit a report in line with the program scope and testing rules.
Test responsibly. Do not access, modify, download, or retain anyone else’s data beyond what is strictly necessary to demonstrate the vulnerability.
01User & Accounts
Login, authentication and access controls
02Data & Privacy
Personal information, credentials and access tokens
03Payments & Transactions
Orders, payments and funds security
04Core Services
Platform features and service stability
Standard rewards
US$50–US$5,000
No fixed cap for critical vulnerabilities
How it works
Program open- 01
Research
Read the program scope and testing rules, and test only with accounts you own or are authorized to use.
- 02
Report
Submit a clear, complete and reproducible description of the issue, with evidence, through the security report form.
- 03
Review & Reward
Our security team validates the issue and assesses the reward based on impact, exploitability, originality and report quality.
Program scope
Before you submit
Use the following criteria to quickly assess whether your finding provides meaningful security value.
What we prioritize
Reports are more likely to qualify for a reward when they involve:
- A previously unknown security vulnerability within the program scope
- A reliably reproducible issue with a clear attack path
- Unauthorized access to, modification of, or deletion of another user’s data
- A bypass of login, verification, or authorization controls, or an account takeover
- Exposure of passwords, tokens, payment information, or other sensitive data
- Demonstrable script execution, server-side code execution, or a clear financial risk
Usually not eligible for a reward
Useful non-security feedback can still be submitted through the appropriate support channel:
- Known issues, or duplicates of an earlier report
- Systems, domains, or third-party assets outside the program scope
- Scanner output or theory without a reproducible result
- Missing recommended settings with no proven security impact
- Page or email styling and wording issues with no real impact
- Orders, refunds, payments, or support requests that are not security issues
How rewards work
Reward assessment
Reward amounts are assessed against the following four criteria.
Standard rewardsUS$50–US$5,000
Critical bugs · no fixed cap
Real impact
Which users, accounts, data, payments or core services could be affected, and the potential scale of loss.
Exploitability
Whether it reproduces reliably, what conditions are required, and how complex the attack or user interaction is.
Originality
Whether the issue was previously unknown, is a duplicate, or is already being fixed.
Report quality
Whether steps, evidence, environment and impact analysis are clear enough for fast validation and remediation.
Vulnerability names, scanner ratings or generic risk levels do not decide the reward; the verified real business impact does.
Reporting requirements
Submit an effective report
A clear, complete report helps us validate the issue quickly, judge its impact and plan a fix. Please include the following six items.
Submit through the GamsGo Security Report FormAffected area
Product, domain, URL, endpoint, account flow or feature location.
Vulnerability summary
The vulnerability type, what happens, and the security risk it creates.
Test environment and steps
Device, browser, account, preconditions, the steps performed and the actual result.
Supporting evidence
Redacted screenshots, recordings, requests, responses, logs or a safe proof of concept.
Real impact
What an attacker could do, who is affected, and the conditions required.
Contact details
Your name and an active email for review feedback and follow-up questions.
Responsible research
Security testing rules
To protect users and the platform, please follow these rules:
- Use only your own or authorized accounts
- Do not access more data than needed to prove the issue
- Stop testing immediately once you reach sensitive data
- No denial-of-service, stress tests, large-scale scanning or brute force
- No social engineering, phishing, spam or deception
- Do not disrupt services, affect users or cause real financial loss
- Mask full passwords, cookies and tokens in screenshots, requests or logs, keeping only what proves the issue
- Do not disclose details publicly before a fix or an agreed disclosure
If you are unsure whether a test is safe or within the program scope, stop testing and contact us through the Security Report Form.
Common questions
Frequently asked questions
No. Only reports that are within the program scope, previously unknown, reproducible, and demonstrably impactful will be considered for a reward. Low-impact issues, duplicate reports, and findings we cannot validate are not normally eligible.
We generally evaluate the first complete report that allows our team to reproduce the issue and confirm its root cause. An earlier timestamp alone does not guarantee priority if the report does not contain enough information.
Yes. If you can demonstrate that an exploitable path remains after a fix, or that the new issue has a different root cause and impact, submit it as a new report and explain how it relates to the original issue.
Report the vulnerability privately through the designated channel and allow reasonable time for investigation and remediation. Do not disclose the details publicly before the issue has been resolved or a disclosure arrangement has been agreed upon by both parties.
Once the report is confirmed as eligible and the necessary remediation or risk controls have been completed, we will use the contact details you provided to confirm the reward and payment information. Complex issues may require additional time to validate and remediate.
Let the bug hunt begin!
Submit vulnerabilities with real security value and help us strengthen the security of GamsGo products and users.
Submit a vulnerability report