> ## Documentation Index
> Fetch the complete documentation index at: https://docs.advinservers.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Bug Bounty

> How to report security vulnerabilities and other bugs in our systems, and how we reward valid reports.

## Overview

If you find a security vulnerability or another bug in the systems we run, please tell us. We reward valid reports, and the reward depends on what the bug is and how much impact it has.

This page is for bugs in our own systems. If your server is down or behaving unexpectedly, see our troubleshooting guides for [network](/troubleshooting/network) and [hardware](/troubleshooting/hardware) problems, or open a normal support ticket. If you are reporting abuse coming from one of our IP addresses, see our [Abuse Policy](/policies/abuse) instead.

## Security Vulnerabilities

### In Scope

We are responsible for the control panel, the hypervisor, and the network, so these systems are in scope:

* The **client area**, at [https://clients.advinservers.com](https://clients.advinservers.com)
* The **Ascienth console**, at [https://vps.advinservers.com](https://vps.advinservers.com), including its [API](/api-reference/introduction)
* Our **hypervisors and network**, as reached from a service on your own account

Examples of what we are looking for:

* Viewing, changing, or deleting another customer's account, services, or data
* Escaping a virtual server to reach the host or another customer's server
* Bypassing authentication or two-factor authentication, or taking over an account
* Reaching admin functions as a customer, or doing more in a team than your role allows
* Using an API key on resources outside its team, or with permissions it was not given
* Remote code execution, SQL injection, or stored cross-site scripting in the client area or console
* Intercepting another customer's traffic, or using IP addresses that are not assigned to you

### Out of Scope

The following are not eligible for a reward:

* Anything inside a customer's server, including the operating system and software on your own server. Our services are unmanaged, so securing them is your responsibility.
* Services run by third parties, such as our payment processors
* Denial-of-service attacks, load testing, or any testing that degrades our services
* Social engineering or phishing of our staff or customers, and physical attacks on our facilities
* Reports from automated scanners without a working proof of concept
* Missing security headers, cookie flags, or email records (SPF, DKIM, DMARC) with no demonstrated impact
* Self-XSS, logout CSRF, or clickjacking on pages without sensitive actions
* Software version disclosure without a working exploit
* Issues that require a compromised device or physical access to the victim's device

## Other Bugs

Bugs that are not security issues are also eligible for a reward. For example:

* Billing errors, such as being charged the wrong amount or a renewal being calculated incorrectly
* A way to get a service, an upgrade, or account credit without paying for it
* A feature in the client area or console that fails, or that behaves differently from our documentation

## Testing Rules

To stay eligible, you must follow these rules while looking for and confirming a bug:

* **Only use your own accounts and services.** If you need a second account to test access between accounts, create one yourself. Its details, including your first name, last name, address, and phone number, must match your original account, as our [Terms of Service](/policies/termsofservice#multiple-accounts) require. Never test against another customer's account or server.
* **Stop once you have confirmed the issue.** If you reach another customer's data, access no more than you need to show the issue, do not keep a copy of it, and report it to us right away.
* **Do not disrupt our services.** Do not run high-volume automated scanners or anything that affects other customers.
* **Do not profit from the bug.** If a bug gives you credit, services, or resources you did not pay for, report it instead of using it. Anything gained through the bug may be removed from your account.
* **Keep it private.** Do not share the details publicly or with anyone else until we have fixed the issue and agreed to disclosure.
* **Follow our policies.** Our [Terms of Service](/policies/termsofservice) and [Abuse Policy](/policies/abuse) still apply while you are testing.

## How to Report

Open a ticket from the [client area](https://clients.advinservers.com/contact.php). Start the subject line with "Security Report" or "Bug Report" so that it reaches the right people.

Include the following so that we can reproduce the bug without asking follow-up questions:

* A short description of the bug and where it is, such as the page URL or API endpoint
* Step-by-step instructions to reproduce it
* What an attacker, or any customer, could do with it
* Evidence, such as screenshots, HTTP requests and responses, or a short video. Paste text rather than screenshots where possible.
* The account and services you used for testing, and the date, time, and **timezone** you tested

### Writing Your Report

Keep your report concise and explain the bug in plain English. A few clear sentences and working reproduction steps are more useful to us than a long, generic write-up.

You may use AI tools to help you find a bug or write your report, but they should not write the whole report for you. You are responsible for everything you submit, so make sure you have reproduced the bug yourself and that every step and claim in your report is accurate.

## Rewards

We pay cash rewards, decided case by case within the ranges below. Higher-impact bugs receive larger rewards.

| Severity | Reward (USD) | Examples |
| - | - | - |
| Critical | \$500 – \$1,500 | Escaping a virtual server, taking over any account, or accessing other customers' data at scale |
| High | \$150 – \$500 | Bypassing two-factor authentication, reaching another customer's services, or getting services without paying |
| Medium | \$50 – \$150 | Stored cross-site scripting, or exposure of limited or low-sensitivity information |
| Low | \$10 – \$50 | Billing miscalculations, broken features, and other bugs with little or no security impact |

<Note>
  Rewards are paid only by **bank transfer** or **PayPal**. We do not pay rewards by any other method. We may pay large rewards in monthly installments over a period of up to 6 months. If we do, we will tell you the schedule when we confirm your reward.
</Note>

We also consider how many customers are affected, how easy the bug is to exploit, and how clear your report is. A report with a working proof of concept and clear reproduction steps is worth more than a theoretical one.

A report is not eligible for a reward if:

* Someone else reported the same issue first, or we were already aware of it
* It is out of scope, as described above
* You broke the testing rules on this page

Whether a report qualifies, and the amount of any reward, is at our discretion.

## After You Report

We will confirm that we have received your report and investigate it. We may ask you for more detail while we do. Once we have confirmed the bug, we will let you know the outcome and any reward, and we will keep you updated until it is fixed.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.