Last updated: 2026-10-08
Program status: Open upon publication of this policy at element.fm/bug-bounty/.
ELEMENT.FM LLC welcomes responsible security research that helps protect our users and their podcasts. We will pay rewards for eligible, previously unknown security vulnerabilities reported under these terms.
Scope
Only the following hostnames are in scope, and only for services operated by ELEMENT.FM LLC:
element.fm— our public website.app.element.fm— our podcast hosting application, including its API endpoints served on this hostname.shows.element.fm— our public podcast shows site.chat.element.fm— our Castor chat application.
This is not wildcard authorization. All other subdomains are out of scope unless explicitly added here. Other domains, third-party infrastructure, payment providers, integrations, and services merely linked from our website are also out of scope. Public source code does not expand testing authorization.
If ownership or scope is unclear, ask us before testing. Reports about out-of-scope assets are welcome, but do not authorize testing or qualify for a reward under this program.
Paid rewards
Rewards are paid in US dollars (USD), with a maximum award of $950 per unique vulnerability. This is a per-vulnerability cap, not a total program budget. We assess severity based on verified impact, affected data, privileges required, and realistic exploitability; a scanner score alone does not determine the award.
| Severity | Reward | Impact examples |
|---|---|---|
| Low | $50–$100 | Limited but demonstrable security impact |
| Medium | $150–$300 | Meaningful, limited compromise of confidentiality or integrity |
| High | $400–$600 | Significant unauthorized access or modification affecting users or systems |
| Critical | $750–$950 | Broad compromise of sensitive data or core systems |
Examples describe impact, not permission to demonstrate it against other users. We will use the smallest safe demonstration to assess potential impact.
We will pay an award within the applicable range when a report meets all eligibility requirements. We will explain the severity and amount in writing. You may request reconsideration with additional impact information without performing further unsafe testing.
Eligibility and duplicates
To qualify for payment:
- Be the first to submit a sufficiently complete report of a vulnerability not already known to us.
- Identify an in-scope security vulnerability with demonstrable impact; theoretical concerns and unverified automated findings alone do not qualify.
- Follow the research rules below and provide enough information for us to validate the issue safely.
- Be at least 18 years old and legally able to receive payment. Employees, current contractors, and anyone who discovered the issue through work performed for ELEMENT.FM are not eligible for rewards.
Multiple reports caused by the same underlying issue generally receive one reward, paid to the first eligible reporter. Distinct root causes or independently affected security boundaries may qualify separately. We will explain duplicate and ineligibility decisions without exposing another researcher’s confidential report.
Payment process
After validation, we will confirm the award and arrange a mutually supported payment method. Our target is to issue payment within 30 calendar days of award confirmation and receipt of required payment and tax information. Any legally required identity or tax information will be requested through an agreed secure channel, not in your initial report.
Researchers are responsible for their own taxes. We cannot make payments prohibited by applicable law or sanctions, and will explain any payment restriction. A reward does not require transferring ownership of your research or accepting unrelated publicity or nondisclosure terms.
Research rules
- Test only in-scope services, using accounts and data you own or have explicit permission to use.
- Keep testing manual or low-volume and non-disruptive. Do not run bulk scans, brute-force attempts, denial-of-service tests, or load tests without prior written approval.
- Do not use social engineering, phishing, physical intrusion, malware, or persistence.
- Do not access, download, alter, or delete another person’s data. If you encounter it accidentally, stop immediately and report with minimal, redacted evidence. Do not explore further or retain unnecessary copies.
- Do not change production settings, publish content on someone else’s behalf, disrupt podcasts, or trigger real charges or financial transactions.
- Stop when you have minimal evidence of the issue. Ask before any validation that could expose sensitive data or affect another user.
- Do not threaten, extort, or demand payment outside these published terms.
Reports that do not qualify for rewards
- Issues affecting only out-of-scope assets or third-party services.
- Missing headers, cookie flags, version disclosures, or other hardening suggestions without demonstrated security impact.
- Vulnerable dependency versions without evidence that the deployed service is affected.
- Self-only issues requiring the reporter to compromise their own account, without impact on another security boundary.
- Cosmetic defects, ordinary broken links, spam, and non-security product bugs.
- Denial-of-service or social-engineering findings obtained through prohibited testing.
We still welcome useful security observations even when they are not reward-eligible.
How to report
Email webmaster@element.fm with the subject Security report — Bug bounty. Do not put sensitive details in the subject or open a public issue.
Include:
- The affected in-scope URL or component.
- A clear description of the issue and its potential impact.
- The smallest safe reproduction using your own data and accounts.
- Redacted screenshots or request details, where helpful; never include live credentials, tokens, or other users’ personal information.
- When you observed the issue and how we can contact you.
If sensitive evidence is necessary, first request a secure transfer method. Do not send it in ordinary email.
We aim to acknowledge reports within 2 business days, provide an initial assessment within 10 business days, and send updates at least every 14 calendar days while a report remains open. These are service targets, not guaranteed resolution deadlines.
Coordinated disclosure
Keep vulnerability details private while we validate and remediate the issue. We aim to agree on a disclosure date within 90 calendar days of the initial report, or sooner once a fix is available. If remediation needs longer, we will request an extension and explain why; there is no automatic or indefinite extension. After 90 days, disclosure does not by itself disqualify an otherwise eligible report, provided it does not expose personal data or live secrets.
We will not publish your name or handle without your permission. A reward does not require you to endorse ELEMENT.FM.
Safe harbor
While this program is open, ELEMENT.FM LLC authorizes good-faith security research that stays within this policy. For that research, we will not initiate legal action or report you to law enforcement. To the extent we control them, we waive restrictions in our Terms of Service that would otherwise prohibit research expressly permitted here; this policy takes precedence for that research only.
If a third party initiates legal action against you for compliant research, we will make clear that it was authorized by us. We cannot authorize testing of third-party systems, bind third parties, or waive applicable laws.
If you make an accidental mistake, stop and contact us promptly. We will evaluate good faith, your efforts to minimize harm, and cooperation rather than treating an accidental deviation as automatically malicious. Ask before proceeding if a planned test is uncertain.
Program changes
We may update, pause, or close the program by posting a notice on this page. Changes apply prospectively and do not reduce eligibility or promised rewards for compliant reports submitted before the change. When the program is paused or closed, do not begin or continue testing without separate written authorization.