Bug bounty
Find a flaw. Get paid.
Report a security flaw in Assessly privately, and we pay you once it's fixed.
The programme
- Who
- By invitation. Anyone who finds a flaw can still report it here.
- Rewards
- Set per report, on severity and impact. Paid after the fix ships.
- In scope
- The web app, the phone and desktop apps, including anti-cheat bypasses.
- First reply
- Within 1 to 2 working days.
Rewards and recognition
What a finding is worth.
Set per report, on the severity we assess, the impact, the proof and how exploitable it is. Paid by UPI in India, or by bank transfer to any country, once the fix ships. Every valid finding also earns hall of fame points: critical 40, high 20, medium 10, low 5.
- 01
Hall of fame
Public credit, with your findings on the record.
The standings → - 02
Verifiable certificate
A signed digital certificate with an ID anyone can check at assessly.in/verify.
- 03
LinkedIn endorsement
A personal endorsement for critical-class findings.
- 04
Cash bounties
Paid by UPI in India, or by bank transfer to any country, once the fix is deployed.
Triage and evaluation
How a report becomes a reward.
- 01
Triage
We acknowledge receipt and perform initial triage within 1 to 2 working days.
- 02
Verification
We reproduce the exploit in a safe staging environment. Severity is evaluated solely by Assessly on actual technical and business impact, not the reporter's self-assessed severity.
- 03
Resolution
For valid findings we implement and test a patch. Cash payouts, certificates, endorsements, and hall-of-fame updates are finalized once the fix is deployed.
Evaluation criteria and exclusions (5)
- First-come, first-served
- Bounties are only paid for previously unreported vulnerabilities. Duplicates or known issues are not eligible for rewards or recognition.
- Roadmap exclusion
- Issues already tracked on our internal roadmap or under active remediation are excluded from rewards.
- Client-side telemetry
- Client-side enforcement (UI hiding, DevTools detection, local restrictions) is bypassable by design and is not high/critical unless paired with a backend exploit or RLS bypass.
- No automated spam
- Scanner-generated reports without manual validation, or purely theoretical concerns, are closed as N/A with no reward.
- Single root cause
- Multiple reports sharing one root cause are grouped and treated as a single submission for a single reward.
Scope
What counts, and what does not.
In scope
What we are looking for
- 01Authentication bypasses and deep session hijacking.
- 02Privilege escalation (e.g., student accessing instructor dashboards).
- 03Breaking out of the Judge0 code execution sandbox.
- 04Exploits that bypass our proctoring and anti-cheat telemetry, on the web, the desktop app or the Android app.
- 05Database IDORs exposing other users' submissions or PII.
Out of scope
Closed as not applicable
- 01Volumetric attacks (DoS/DDoS) against Assessly endpoints.
- 02Social engineering against Assessly staff, instructors, or students.
- 03Theoretical issues without a demonstrable exploit chain.
- 04Missing security headers, SPF/DMARC records, or basic IT hygiene issues.
Rules of engagement
Test hard, test fairly.
Real students take real tests on Assessly. Never put their data or their sessions at risk.
By submitting a report to Assessly, you agree to the following:
- 01Keep all vulnerability information strictly confidential until we resolve it.
- 02Do not exploit vulnerabilities beyond the minimum necessary to verify them.
- 03Delete any sensitive data obtained through testing immediately after reporting.
- 04Allow us reasonable time to address the issue before any disclosure.
- 05Remove any public disclosure of vulnerabilities that put Assessly at risk, a strict condition of payment.
Safe harbor
- We will consider security research and vulnerability disclosure conducted in good faith under this policy to be authorized, and we will not pursue or support legal action against you for it.
- If a third party brings legal action against you for activity that complied with this policy, we will make it known that your testing was authorized.
- Good faith means staying within the scope above, accessing or modifying only the minimum data needed to demonstrate a finding, never degrading the service for real users, and giving us reasonable time to remediate before any disclosure.
- This authorization does not cover out-of-scope activity (denial-of-service, social engineering, or accessing real student data) or anything that breaks applicable law.
Joining the programme
By invitation, for now.
Researchers join the programme by invitation. To ask for one, write to hello@assessly.in with a link to your past reports.
Invited researchers can ask for a sandbox college, so they can test the exam side without touching real students. We approve each sandbox by hand.
Submit a report
Found something? Tell us.
We reply to most reports within 1 to 2 working days. Prefer email? Send the same details to hello@assessly.in.
Scope and rules are above. See who's already on the hall of fame.