SECURITY POLICY

Vulnerability Disclosure

Last Revised: September 23, 2026

CrowdCent runs code, holds credits, and can place trading orders on behalf of its members. We welcome reports from researchers who find weaknesses in these systems and we will work with you to fix them. This policy explains how to report a vulnerability, what we cover, the rules for testing, and how we recognise reports. It is the Security Policy referred to in Section 14.4 of the Terms and Conditions.

1. HOW TO REPORT

Email [email protected] with the subject line "Security". Include:

  • A description of the vulnerability and the affected URL, endpoint, or component;
  • The impact: what an attacker could read, change, or spend;
  • Steps to reproduce or a working proof of concept;
  • The account or project you used for testing, and whether you wish to be credited.

We do not currently offer an encrypted reporting channel. Do not include another person's data in a report; describe what you could reach instead.

2. WHAT TO EXPECT

  • Acknowledgement of your report within three (3) business days;
  • An initial assessment of validity and severity within seven (7) days;
  • A target of a fix within ninety (90) days of the report, sooner for severe issues;
  • Updates on our progress until the issue is resolved;
  • Credit in the Acknowledgements below once the issue is fixed, unless you ask to remain anonymous.

3. SCOPE

3.1 IN SCOPE
  • crowdcent.com and the CrowdCent API;
  • CrowdCent Cloud, including escape from a run or session sandbox; access to another user's projects, files, sessions, secrets, or runs; the egress relay and proxy; and signed upload and download URLs;
  • Centaur, where content such as a file, web page, or tool output causes Centaur to perform an action without the approval that action requires;
  • Authentication, session handling, and account takeover;
  • Any means of spending another user's credits, or of placing, changing, or cancelling another user's trading orders;
  • The CrowdCent MCP server and API keys.
3.2 OUT OF SCOPE
  • Denial of service and volumetric or load testing;
  • Automated scanning at volume;
  • Social engineering, including phishing, of CrowdCent staff or members;
  • Physical attacks against offices, people, or equipment;
  • Spam, or sending messages to other members;
  • Missing security headers or other best-practice configuration without a demonstrated impact;
  • Vulnerabilities in third-party services, including Google Cloud, Hyperliquid, and AI model providers, which should be reported to those parties;
  • Output of automated tools without a working proof of concept.

4. RULES FOR TESTING

  • Test only against accounts and projects that you own;
  • Never access, modify, retain, or disclose another user's data. If you reach it, stop at the first proof that access is possible and report;
  • After demonstrating a sandbox escape, do not mine cryptocurrency, establish persistence, or move laterally to other systems;
  • Test the Trading Services only with your own funds and the smallest practicable order sizes;
  • Do not degrade the service for other users;
  • Report a vulnerability within twenty-four (24) hours of confirming it;
  • Do not disclose a vulnerability publicly until it is fixed or ninety (90) days have passed since your report, whichever is earlier, and coordinate the timing of disclosure with us.

5. SAFE HARBOR

Security research conducted in good faith and in compliance with this policy is authorised by CrowdCent and does not breach Sections 5.4, 12.11, or 13.7 of the Terms and Conditions. We will not initiate or recommend legal action against you for it, and if a third party brings legal action against you for it, we will make known that the research was authorised. We will not suspend, terminate, or penalise your account or remove your points, streaks, or rewards, in respect of such research. This authorisation covers only systems operated by CrowdCent; we cannot authorise testing of third-party systems. Research that does not comply with this policy is not covered. If you are unsure whether an activity is permitted, ask us at [email protected] before proceeding.

6. REWARDS

Rewards are discretionary and based on the severity of the issue and the quality of the report. Severity is judged by what an attacker could reach: another member's data, credits, or trading orders, or CrowdCent's own systems. Rewards are paid in CrowdCent Cloud credits or, for high and critical issues, in cash by agreement. Typical amounts are:

  • Low (no access to another member's data, credits, or orders): up to US $50 in credits;
  • Medium (could reach another member's data, credits, or orders in limited circumstances): US $50 to $250 in credits;
  • High (reliably reaches another member's data, secrets, credits, or orders): US $250 to $1,000;
  • Critical (escape from the sandbox, access across all members, or control of CrowdCent's systems or funds): US $1,000 or more, by agreement.

Ordinary bugs are welcome too. A report of broken scoring, points, or submissions, a Cloud run or schedule that fails through no fault of its code, or a charge that does not match the billing page earns US $5 to $50 in credits; a broken link, email, or display issue earns up to US $5 in credits. These are not security issues and need not follow Section 4.

No reward is paid for out-of-scope or duplicate reports; where two reports describe the same issue, the first received is eligible. CrowdCent employees and contractors are not eligible. To receive a reward you must meet the sanctions and compliance representations in Section 2.1 of the Terms and Conditions. Whether a report qualifies, its severity, and the amount of any reward are decided by CrowdCent, and that decision is final. You must hold a CrowdCent account to receive a reward, and credits are paid to that account. You are responsible for any taxes on a reward; a United States person receiving more than US $600 in a calendar year must provide a Form W-9 before payment. Credits paid as a reward are subject to Section 13.6 of the Terms and Conditions. We may change or end this rewards programme at any time; a change does not affect a report received before it.

7. ACKNOWLEDGEMENTS

No reports have been acknowledged on this list yet.