Found a security vulnerability? This page is your central point of contact for all security-related reports.
If you have discovered a security vulnerability:
📧 Email: security@meingpt.com
📝 Subject: URGENT - Critical Security Issue (for critical issues)
- A detailed description of the vulnerability
- Steps to reproduce the issue
- Potential impact and a risk assessment
- Screenshots or code examples, if possible
We prioritize reports by severity and respond as quickly as possible.
We reward security researchers who responsibly find and report vulnerabilities in our systems.
The amount is based on:
- Severity of the vulnerability (Critical, High, Medium, Low)
- Quality of the report (reproducibility, documentation, clarity)
- Potential impact on users and systems
- First report (only the first valid report is rewarded)
- Web applications and APIs (app.meingpt.com)
- Authentication and authorization
- Data leaks and privacy violations
- SQL injection, XSS, CSRF
- Remote code execution
- Authentication bypass
- Privilege escalation
- Expired SSL/TLS certificates – we appreciate the report, but it doesn't qualify for a bounty
- Missing security headers without demonstrated impact
- Self-XSS requiring user interaction
- Social engineering attacks
- DoS/DDoS attacks
- SPF/DMARC/DKIM issues without demonstrated exploitability
- Rate-limiting issues without security impact
- Vulnerabilities in third-party systems (report directly to the vendor)
- Issues in deprecated or end-of-life features
- Theoretical vulnerabilities without a proof of concept
- Paywall/feature-gating bypasses that don't lead to unauthorized data access
- HackerOne Core Ineligible Findings↗
Contact us for the current terms of the Bug Bounty Program: security@meingpt.com
We'll then discuss individually:
- The scope of allowed tests
- Testing methods
- Reporting procedures
- The verification process
- Don't access, modify, or delete user data. Use our staging environment at staging.meingpt.com to make sure you don't accidentally access real user data.
- Avoid service disruption – no DoS attacks or resource exhaustion.
- One vulnerability per report – separate issues need separate reports.
- Allow time for patching – coordinate the disclosure timeline with our team.
- Comply with all applicable laws – unauthorized access is prohibited.
- Report in good faith – no extortion or threats.
- Test accounts only – use accounts you control.
The following will result in immediate disqualification from the program and may lead to legal action:
- Public disclosure before resolution
- Attempted extortion
- Testing on production systems without authorization
- Accessing customer data
- Social engineering of employees
- Physical attacks on our infrastructure
- Coordinated disclosure after successful resolution
- Recognition in our Hall of Fame
- Legal protection for researchers who report responsibly
- Constructive collaboration with our security team
- Accessing customer data without permission
- Denial-of-service attacks
- Social engineering of employees
- Physical attacks on our infrastructure
We thank all security researchers who have helped improve MeinGPT. With their consent, we publish their names here.
For security reasons, we don't publish details of individual vulnerabilities.