Back

Security Program

Prop Firm Match Bug Bounty Program

Prop Firm Match runs an open bug bounty program to improve the security of our platform. This program is aimed at software developers, technical leads, DevOps engineers, and independent security researchers. We welcome reports of security issues across our entire system. In exchange for finding valid bugs, researchers receive public recognition, swag, and even cash rewards For example, many programs “offer prizes, ranging from public recognition, inclusion in halls of fame, free merch and swag to monetary rewards”.

Scope

All Prop Firm Match assets are in scope. This includes the main website propfirmmatch.com and all its subdomains along with pf1, web/mobile applications (iOS/Android apps and APIs), and backend services. We also include our infrastructure: for example, the AWS environment (S3 buckets, IAM policies/roles, API Gateway endpoints, EC2 instances, Lambda functions, databases, etc.) used by Prop Firm Match. In general, our in-scope assets cover all web domains, IPs, APIs, mobile apps, and systems under Prop Firm Match control. If you identify any Prop Firm Match system not explicitly listed here, it is likely in scope so feel free to ask before probing it.

Reporting a Vulnerability

Submit bugs by emailing security@propfirmmatch.com or using our internal security submission portal. Every report should include:

  • Detailed description and reproduction steps. Explain the issue clearly and concisely. Provide a step-by-step guide or proof-of-concept code to demonstrate the problem.
  • Affected component(s). Specify the URL(s), API endpoints, subdomains, or services involved.
  • Impact assessment. Describe what an attacker could achieve (data exposed, operations bypassed, etc.) Explain the potential consequences of the bug.
  • Any relevant context. For example, authentication levels, browser or OS versions, or data examples. Providing this information up front helps us triage and reproduce the issue quickly. If you include contact information (e.g an email address), we will acknowledge receipt of your report.

Triage and Response

Once a report is received, our security team will acknowledge and triage it within 48 hours. During triage, we validate the finding, classify its severity, and create an internal bug-tracker ticket. We then promptly notify the relevant engineering team or product owner to begin remediation. Communication with the researcher continues throughout and we may request clarifications or additional details as needed. Our goal is to process new reports quickly PFM's guidance is to reply within days and close within weeks. and we strive to meet or exceed that pace.

Severity Levels & SLAs

We classify valid issues into Critical, High, Medium, or Low severity. These roughly follow industry definitions:

  • Critical: Flaws that allow full system compromise or immediate data theft. For example, unauthenticated Remote Code Execution, admin password bypass, or exposure of large amounts of sensitive user data. We commit to fixing Critical vulnerabilities within 24-72 hours of verification.
  • High: Hard-to-exploit bugs that can still cause major harm - e.g. privilege escalation, critical business-logic bypass, or substantial data leakage. We aim to remediate High issues within 7 calendar days.
  • Medium: Less severe vulnerabilities, like cross-site scripting (XSS), cross-site request forgery (CSRF) on non-critical actions, or minor information leaks. These typically require user interaction or have limited impact. We fix Medium issues within 14 days.
  • Low: Minor issues with little real impact, such as trivial information disclosures, clickjacking on non-sensitive pages, or low-risk misconfigurations. We address Low issues within 30 days.

If any fix deadline is missed, the issue is escalated to the Engineering Manager and the Security Lead. This ensures high-priority bugs get the attention they need.

Remediation & Testing

Scaling chances link to steady profits in different market conditions. Strong trends can speed up scaling, while sideways markets make it tough to meet goals without risking steady performance. Knowing the market helps traders pick strategies that work best for long-term growth.
Key Focus: Steady profits, even small ones, build a solid base for scaling while guarding against big losses. Being able to change is key for lasting growth.

Verification & Closure

After deployment, the security team re-tests the patch by reproducing the original steps. If the issue is resolved, we update our internal ticket (and mark the report “Resolved”). We then notify the researcher of the outcome and thank them for their contribution. If the researcher agrees to disclosure, we credit them in our release notes or public changelog when we update the product. All closure steps are documented in our issue tracker for audit purposes.

Post-Fix Activities

For every Critical or High bug, we perform a formal root-cause analysis (RCA). This involves a security post-mortem to identify why the flaw occurred and how to prevent similar issues. We share the findings with the engineering team in a “security sync” meeting or retrospective. If necessary, we update our secure coding guidelines and run training sessions to address the root causes. This continuous feedback loop helps improve our codebase and practices over time.

Continuous Improvement

We regularly review the bug bounty program itself. At least once per quarter we analyze submission trends, response times, and reward effectiveness, and update the program rules as needed. Lessons learned from bounty reports feed into our threat modeling: we encourage developers and architects to revise threat models or design reviews based on real bugs. By involving dev teams in these reviews, we proactively harden the system and prevent repeat vulnerabilities.

Rewards

Valid reports earn public recognition and rewards. Specifically:

  • Hall of Fame: Every unique valid submission (Critical through Low) will be acknowledged in our “Hall of Fame” on the public site. (This shows we appreciate all contributions.)
  • Swag: For High and Critical findings, we send company swag (t-shirts, stickers, etc.) as a thank-you. This matches common practice where bounty programs give out merchandise to notable reporters.
  • Monetary Bounty / Credit: In special cases (particularly impactful High/Critical bugs), we may offer a cash reward or a credit toward a Prop Firm Match account. Bounties can be up to $5,000 for outstanding Critical/High issues, at our discretion.

Out-of-Scope Vulnerabilities

Certain issues are not eligible for rewards. These are usually findings with no practical security impact or general best-practice suggestions. Out-of-scope examples include:

  • Missing rate limiting without exploit. For example, lack of a rate limit on login is only in scope if it can be exploited. A generic missing rate-limit with no working exploit is not rewarded.
  • Clickjacking on non-sensitive pages. If a page contains no state-changing or sensitive actions, a clickjacking finding is not valid. (E.g clickjacking an informational static page.)
  • CSRF on trivial actions. CSRF affecting a logout or other harmless action is out-of-scope. Only CSRF that leads to sensitive state changes is eligible.
  • Outdated libraries or missing hardening without risk. Merely using an old library version (with no known exploitability) or missing a security header is not rewarded. We reward only vulnerabilities that can actually be exploited.
  • Information leakage. Generic disclosures like publicly visible version banners, error messages, or server headers with no direct security impact are out-of-scope.
  • Automated scan findings without PoC. Reports based only on static/tool scanning (e.g. SSL/TLS config, CSV injection warnings, cookie flags) that lack a demonstrated exploit are not valid.
  • Social engineering or physical attacks. Attempts that rely on tricking our staff or physically accessing devices are prohibited.

Any vulnerability without a clear security impact or requiring disallowed testing is considered out-of-scope. Our aim is to encourage focus on real, exploitable flaws. The core ineligible list on HackerOne likewise closes “clickjacking on pages with no sensitive actions” and “most issues related to rate limiting” as invalid.

Contact

If you have questions about the bounty program, email our security team at security@propfirmmatch.com.

    Security & Bug Bounty Program Details | Prop Firm Match | Prop Firm Match