Responsible disclosure & bug bounty policy
Should you find a vulnerability in New York Proxies, we want to hear about it. Scope, payable issues, non-payable issues and reporting steps are all set out here, so neither side hits a surprise.
Scope
In scope
- This website,
newyorkproxies.com - The logged-in customer dashboard and the API that comes with it
- Rotation links, API keys and proxy credentials, as the dashboard handles them
Out of scope
- Proxy gateways and modem hosts, and the mobile carrier networks under them
- Anything run by a third party: payment processors, Telegram, Cloudflare, email providers
- Marketing assets served from legacy CDN paths
- Anybody else's customer account or data
What we pay
Rewards follow demonstrated impact on our systems or customers. Amounts are in USD.
- Remote code execution on our servers
- SQL injection into customer data, read or write
- An authentication bypass that lets you into any account without its credentials
- Proxies, credit or refunds obtained without paying, through payment or balance manipulation
- Exposing other customers' proxy credentials or personal data in bulk
- IDOR access to another customer's proxies, orders or account details, to read or change them
- Stored cross-site scripting triggered in an admin's or another customer's session
- Privilege escalation out of a customer account and into admin functions
- Server-side request forgery reaching internal services
- Theft of a rotation link, API key or session from another account
- A cross-site request forgery that can change an account's state
- Reflected cross-site scripting that can't trigger until the victim clicks a link
- Rate-limit bypass leading to an account takeover that is demonstrated
- Business-logic and pricing errors with a financial impact you can demonstrate
Acknowledgment and a fix where warranted, but no payment. Scan the full list below before you start the report.
Rules of engagement
- First valid report wins. Duplicates, and reports on issues we already know, are unpaid. One root cause gets one payment, even across multiple endpoints.
- Prove it, then stop. Access only your own accounts and data. Once a test would expose someone else's data, stop at the first proof and report; no pivoting, downloading or persisting.
- Do not degrade the service. Load testing, volume fuzzing by automation and tests on proxy gateways, modem hosts or carrier networks are barred. Those are out of scope entirely.
- Give us time. Hold publication until the issue is fixed by us and 30 days have passed. Expect word from us when a fix is live.
- Severity is ours to set. Our reference is the Bugcrowd Vulnerability Rating Taxonomy, applied to the impact on our own systems. At our discretion and within the ranges above, we set the amount and pay it by PayPal or USDT.
What we do not pay for
We accept these as Low or Informational, and no higher. We'll read them and fix what merits fixing, but no bounty follows, Critical or High label or not.
- Logout, password reset or password change leaving a session open until its token expires
- Missing or “weak” CSP, HSTS, X-Frame-Options or Referrer-Policy headers that come without a working exploit
- Pages with no sensitive action being open to clickjacking
- Attributes of cookies that are not session cookies
- Enumeration of usernames or emails, including timing- or error-message-based
- Forgot-password, login and rate-limit observations missing a demonstrated account takeover
- Password policy critiques: length, complexity, common-password lists, lack of forced rotation
- 2FA that is optional, or two-factor authentication not offered at all
- Self-XSS, plus XSS the attacker can only trigger in a session of their own
- CSRF in non-sensitive forms like login, logout and language
- Open redirects that never leak a token or a credential
- Stack traces, server banners, software versions or path disclosures without sensitive data
- SPF, DKIM or DMARC configuration reports
- Automated scanner results that have no proof of concept
- Brute-force attempts, denial of service, resource exhaustion or any test that loads the system
- Phishing or social engineering of our staff or customers, and any physical attack
- Third-party issues at services we use: payment processors, Telegram, Cloudflare, email providers
- Library versions behind the latest, without a working exploit against our deployment
- Attacks that call for a compromised device, a rooted phone or a man-in-the-middle position
- Duplicates of known issues, best-practice recommendations and theoretical risks
How to report
Email [email protected] with the subject Security report. Name the affected URL and the account you used, and add exact reproduction steps and a proof of concept. Within 5 business days you get our acknowledgment, and within 10 business days our severity decision.
Machine-readable contact details are at /.well-known/security.txt.
Send a reportPolicy last updated 2026-10-10.
