Skip to content

Bug bounty

Find a flaw. Get paid.

Report a security flaw in Assessly privately, and we pay you once it's fixed.

The programme

Who
By invitation. Anyone who finds a flaw can still report it here.
Rewards
Set per report, on severity and impact. Paid after the fix ships.
In scope
The web app, the phone and desktop apps, including anti-cheat bypasses.
First reply
Within 1 to 2 working days.

Rewards and recognition

What a finding is worth.

Set per report, on the severity we assess, the impact, the proof and how exploitable it is. Paid by UPI in India, or by bank transfer to any country, once the fix ships. Every valid finding also earns hall of fame points: critical 40, high 20, medium 10, low 5.

  1. 01

    Hall of fame

    Public credit, with your findings on the record.

    The standings →
  2. 02

    Verifiable certificate

    A signed digital certificate with an ID anyone can check at assessly.in/verify.

  3. 03

    LinkedIn endorsement

    A personal endorsement for critical-class findings.

  4. 04

    Cash bounties

    Paid by UPI in India, or by bank transfer to any country, once the fix is deployed.

Triage and evaluation

How a report becomes a reward.

  1. 01

    Triage

    We acknowledge receipt and perform initial triage within 1 to 2 working days.

  2. 02

    Verification

    We reproduce the exploit in a safe staging environment. Severity is evaluated solely by Assessly on actual technical and business impact, not the reporter's self-assessed severity.

  3. 03

    Resolution

    For valid findings we implement and test a patch. Cash payouts, certificates, endorsements, and hall-of-fame updates are finalized once the fix is deployed.

Evaluation criteria and exclusions (5)
First-come, first-served
Bounties are only paid for previously unreported vulnerabilities. Duplicates or known issues are not eligible for rewards or recognition.
Roadmap exclusion
Issues already tracked on our internal roadmap or under active remediation are excluded from rewards.
Client-side telemetry
Client-side enforcement (UI hiding, DevTools detection, local restrictions) is bypassable by design and is not high/critical unless paired with a backend exploit or RLS bypass.
No automated spam
Scanner-generated reports without manual validation, or purely theoretical concerns, are closed as N/A with no reward.
Single root cause
Multiple reports sharing one root cause are grouped and treated as a single submission for a single reward.

Scope

What counts, and what does not.

In scope

What we are looking for

  • 01Authentication bypasses and deep session hijacking.
  • 02Privilege escalation (e.g., student accessing instructor dashboards).
  • 03Breaking out of the Judge0 code execution sandbox.
  • 04Exploits that bypass our proctoring and anti-cheat telemetry, on the web, the desktop app or the Android app.
  • 05Database IDORs exposing other users' submissions or PII.

Out of scope

Closed as not applicable

  • 01Volumetric attacks (DoS/DDoS) against Assessly endpoints.
  • 02Social engineering against Assessly staff, instructors, or students.
  • 03Theoretical issues without a demonstrable exploit chain.
  • 04Missing security headers, SPF/DMARC records, or basic IT hygiene issues.

Rules of engagement

Test hard, test fairly.

Real students take real tests on Assessly. Never put their data or their sessions at risk.

By submitting a report to Assessly, you agree to the following:

  1. 01Keep all vulnerability information strictly confidential until we resolve it.
  2. 02Do not exploit vulnerabilities beyond the minimum necessary to verify them.
  3. 03Delete any sensitive data obtained through testing immediately after reporting.
  4. 04Allow us reasonable time to address the issue before any disclosure.
  5. 05Remove any public disclosure of vulnerabilities that put Assessly at risk, a strict condition of payment.

Safe harbor

  • We will consider security research and vulnerability disclosure conducted in good faith under this policy to be authorized, and we will not pursue or support legal action against you for it.
  • If a third party brings legal action against you for activity that complied with this policy, we will make it known that your testing was authorized.
  • Good faith means staying within the scope above, accessing or modifying only the minimum data needed to demonstrate a finding, never degrading the service for real users, and giving us reasonable time to remediate before any disclosure.
  • This authorization does not cover out-of-scope activity (denial-of-service, social engineering, or accessing real student data) or anything that breaks applicable law.

Joining the programme

By invitation, for now.

Researchers join the programme by invitation. To ask for one, write to hello@assessly.in with a link to your past reports.

Invited researchers can ask for a sandbox college, so they can test the exam side without touching real students. We approve each sandbox by hand.

Submit a report

Found something? Tell us.

We reply to most reports within 1 to 2 working days. Prefer email? Send the same details to hello@assessly.in.

Scope and rules are above. See who's already on the hall of fame.

Impact assessment Select all that apply

Responsible disclosure terms

By submitting a vulnerability to Assessly, you acknowledge that you have read and agree to our responsible disclosure terms, including the strict requirement to remove any public disclosures of vulnerabilities as a condition of payment. You agree to allow us reasonable time to address the issue before any disclosure.