Overview
If you find a security vulnerability or another bug in the systems we run, please tell us. We reward valid reports, and the reward depends on what the bug is and how much impact it has. This page is for bugs in our own systems. If your server is down or behaving unexpectedly, see our troubleshooting guides for network and hardware problems, or open a normal support ticket. If you are reporting abuse coming from one of our IP addresses, see our Abuse Policy instead.Security Vulnerabilities
In Scope
We are responsible for the control panel, the hypervisor, and the network, so these systems are in scope:- The client area, at https://clients.advinservers.com
- The Ascienth console, at https://vps.advinservers.com, including its API
- Our hypervisors and network, as reached from a service on your own account
- Viewing, changing, or deleting another customer’s account, services, or data
- Escaping a virtual server to reach the host or another customer’s server
- Bypassing authentication or two-factor authentication, or taking over an account
- Reaching admin functions as a customer, or doing more in a team than your role allows
- Using an API key on resources outside its team, or with permissions it was not given
- Remote code execution, SQL injection, or stored cross-site scripting in the client area or console
- Intercepting another customer’s traffic, or using IP addresses that are not assigned to you
Out of Scope
The following are not eligible for a reward:- Anything inside a customer’s server, including the operating system and software on your own server. Our services are unmanaged, so securing them is your responsibility.
- Services run by third parties, such as our payment processors
- Denial-of-service attacks, load testing, or any testing that degrades our services
- Social engineering or phishing of our staff or customers, and physical attacks on our facilities
- Reports from automated scanners without a working proof of concept
- Missing security headers, cookie flags, or email records (SPF, DKIM, DMARC) with no demonstrated impact
- Self-XSS, logout CSRF, or clickjacking on pages without sensitive actions
- Software version disclosure without a working exploit
- Issues that require a compromised device or physical access to the victim’s device
Other Bugs
Bugs that are not security issues are also eligible for a reward. For example:- Billing errors, such as being charged the wrong amount or a renewal being calculated incorrectly
- A way to get a service, an upgrade, or account credit without paying for it
- A feature in the client area or console that fails, or that behaves differently from our documentation
Testing Rules
To stay eligible, you must follow these rules while looking for and confirming a bug:- Only use your own accounts and services. If you need a second account to test access between accounts, create one yourself. Its details, including your first name, last name, address, and phone number, must match your original account, as our Terms of Service require. Never test against another customer’s account or server.
- Stop once you have confirmed the issue. If you reach another customer’s data, access no more than you need to show the issue, do not keep a copy of it, and report it to us right away.
- Do not disrupt our services. Do not run high-volume automated scanners or anything that affects other customers.
- Do not profit from the bug. If a bug gives you credit, services, or resources you did not pay for, report it instead of using it. Anything gained through the bug may be removed from your account.
- Keep it private. Do not share the details publicly or with anyone else until we have fixed the issue and agreed to disclosure.
- Follow our policies. Our Terms of Service and Abuse Policy still apply while you are testing.
How to Report
Open a ticket from the client area. Start the subject line with “Security Report” or “Bug Report” so that it reaches the right people. Include the following so that we can reproduce the bug without asking follow-up questions:- A short description of the bug and where it is, such as the page URL or API endpoint
- Step-by-step instructions to reproduce it
- What an attacker, or any customer, could do with it
- Evidence, such as screenshots, HTTP requests and responses, or a short video. Paste text rather than screenshots where possible.
- The account and services you used for testing, and the date, time, and timezone you tested
Writing Your Report
Keep your report concise and explain the bug in plain English. A few clear sentences and working reproduction steps are more useful to us than a long, generic write-up. You may use AI tools to help you find a bug or write your report, but they should not write the whole report for you. You are responsible for everything you submit, so make sure you have reproduced the bug yourself and that every step and claim in your report is accurate.Rewards
We pay cash rewards, decided case by case within the ranges below. Higher-impact bugs receive larger rewards.Rewards are paid only by bank transfer or PayPal. We do not pay rewards by any other method. We may pay large rewards in monthly installments over a period of up to 6 months. If we do, we will tell you the schedule when we confirm your reward.
- Someone else reported the same issue first, or we were already aware of it
- It is out of scope, as described above
- You broke the testing rules on this page