Our bug bounty program allows ethical hackers and security researchers to earn rewards for discovering and reporting security vulnerabilities in our software.
Our bug bounty program is limited to our production services and includes public-facing web applications, and APIs developed by us. Unfortunately, we cannot accept reports for third-party administered applications or websites at this time. *Note that our Marketing site ‘Tecton.ai’ is also explicitly not included in this program as it is administered by a 3rd party. The following systems are considered in-scope:
Any service not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this policy’s scope and should be reported directly to the vendor according to their disclosure policy (if any). If you aren’t sure whether a system is in scope or not, contact us at security@tecton.ai before starting your research.
Though we develop and maintain other internet-accessible systems or services, we ask that active research and testing only be conducted on the systems and services covered by the scope of this document. If there is a particular system not in scope that you think merits testing, please contact us to discuss it first. We will increase the scope of this policy over time.
Under this policy, “research” means activities in which you:
The following test methods are not authorized:
We offer rewards from a range of $100 to $500 for qualifying bugs. Existing and known bugs are not paid. The amount awarded will depend on the severity and impact of the vulnerability. Severity of vulnerabilities is determined using CVSS 4.0.
To report a bug, please email security@tecton.ai. Submissions should include at minimum a summary and steps to reproduce the issue. We aim to respond within 3 business days and resolve valid reports within 14 days.
If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized. We will work with you to understand and resolve the issue quickly, and Tecton will not recommend or pursue legal action related to your research. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.
Unfortunately, Tecton does not currently support these clouds. We’ll make sure to let you know when this changes!
However, we are currently looking to interview members of the machine learning community to learn more about current trends.
If you’d like to participate, please book a 30-min slot with us here and we’ll send you a $50 amazon gift card in appreciation for your time after the interview.
or
Interested in trying Tecton? Leave us your information below and we’ll be in touch.
Unfortunately, Tecton does not currently support these clouds. We’ll make sure to let you know when this changes!
However, we are currently looking to interview members of the machine learning community to learn more about current trends.
If you’d like to participate, please book a 30-min slot with us here and we’ll send you a $50 amazon gift card in appreciation for your time after the interview.
or
Interested in trying Tecton? Leave us your information below and we’ll be in touch.
Unfortunately, Tecton does not currently support these clouds. We’ll make sure to let you know when this changes!
However, we are currently looking to interview members of the machine learning community to learn more about current trends.
If you’d like to participate, please book a 30-min slot with us here and we’ll send you a $50 amazon gift card in appreciation for your time after the interview.
or