Survicate Security

Bug Bounty Program

Effective date: 14.07.2026

§1. Objective (Competitive Program)

The Survicate S.A. Bug Bounty Program (the “Program”) aims to enhance the security of Survicate’s products and services by encouraging security researchers to identify vulnerabilities (the “Vulnerabilities”) in a responsible manner. The Program also aims to improve security for all users by enabling Survicate to assess and remediate Vulnerabilities.

The Program is competitive in nature. Submissions are assessed against each other for quality, impact, completeness, and usefulness to Survicate. Only selected submissions may receive a monetary reward, as determined solely at Survicate’s discretion. Participation in the Program and/or submission of a report does not guarantee a reward, even if a report is valid.

§2. Definitions

Survicate S.A. – the Program’s organizer, based at ul. Zamiany 8 LU2, 02–786 Warsaw, Poland, entered into the register of entrepreneurs of the National Court Register kept by the District Court for the capital city of Warsaw in Warsaw, 13th Commercial Division of the National Court Register under KRS number: 0001021023, NIP number: 9512390641, fully paid-up share capital: PLN 300,000.00; Program contact e-mail address: bugbounty@survicate.com.

Participant – any individual who meets the eligibility criteria and engages in identifying and reporting Vulnerabilities.

Vulnerability – any security issue identified within Survicate’s online services and infrastructure that could lead to unauthorized access, data breaches, or other forms of compromise, constituting a unique submission of which Survicate had no prior knowledge.

Reward – financial or other compensation provided to Participants only for selected submissions, as determined by Survicate in its sole discretion, for valid Vulnerabilities reported in accordance with these Terms.

PayPal Account – a PayPal account held by the Participant and capable of lawfully receiving the relevant payout.

§3. Participation Requirements

By reporting Vulnerabilities, you agree to the terms of this Program.

Participants must be at least 18 years old and possess full legal capacity.

Current or former employees of Survicate S.A., its affiliates, or anyone involved in the development, administration, or operation of Survicate services, as well as their immediate family members, are excluded from participating.

Participants must comply with all applicable laws, regulations, and ethical rules when conducting security testing. Vulnerabilities must be reported in good faith and must not involve malicious intent to compromise the confidentiality, integrity, or availability of Survicate systems. Participants must refrain from any actions that are invasive, destructive, deceptive, or otherwise disproportionate to the purpose of documenting the Vulnerability.

The Participant is responsible for providing all necessary tools and resources required to participate in the Program and acknowledges that participation in the Program is entirely at their own cost and risk.

Efforts to gather information about vulnerabilities are not rewarded, meaning that merely dedicating time without delivering a valid and useful result is not sufficient for recognition or Reward.

Participation in the Program is available only where Survicate can lawfully and practically operate the Program and, where applicable, lawfully and technically make a payout.

Survicate may deny participation, deny a Reward, suspend payment, or request additional verification where necessary due to applicable sanctions, export control rules, fraud prevention requirements, payment provider restrictions, technical unavailability of PayPal payout functionality, tax compliance requirements, or other legal or compliance reasons.

A Participant is eligible for a monetary Reward only if:

  1. the Participant is not located in, resident in, or otherwise subject to a jurisdiction in respect of which applicable law, sanctions, or payment restrictions prevent participation or payout;
  2. the Participant can receive payout through PayPal in accordance with these Terms and applicable PayPal rules and functionality for the relevant country or account type;
  3. the Participant provides accurate and complete payout and tax information when requested; and
  4. the Participant successfully completes any payout verification required under §7.

Survicate reserves the right to restrict, suspend, or permanently exclude any Participant who repeatedly submits reports that are out of scope, of insufficient quality, duplicative, or otherwise not useful to the Program. Creating multiple accounts or using multiple identities to circumvent such restrictions will result in permanent disqualification from the Program.

§4. Scope of the Program (Targets)

The following products and services are included in the Program: all online services and applications provided by Survicate S.A., according to the following list:

  1. In-scope hosts:
    • panel.survicate.com
    • panel-api.survicate.com
    • survey.survicate.com
    • surveys-static.survicate.com
    • surveys-static-prd.survicate-cdn.com
    • respondent.survicate.com
  2. In-scope apps:
    • iOS SDK
    • Android SDK
    • React Native SDK
    • Flutter SDK
    • JavaScript SDK
    • Panel – panel.survicate.com
    • Data Export API v2 only
    • Webhooks

Any domains, endpoints, assets, applications, or environments not listed in the Targets section are out of scope.

Third-party integrations and external services not directly controlled by Survicate are excluded from the Program.

Vulnerabilities in the following areas are out of scope and will not be eligible for Rewards:

  1. Vulnerabilities in third-party applications or libraries that are not developed by Survicate.
  2. Exploitation of known vulnerabilities that depend on outdated user software, such as outdated browsers or operating systems.
  3. Distributed Denial of Service (DDoS) attacks.
  4. Vulnerabilities related to third-party APIs.
  5. Brute-force attacks to uncover credentials.
  6. Social engineering, phishing, impersonation, or other tactics unrelated to the technical security of Survicate systems.
  7. Issues with DNS records (including SPF, DKIM, DMARC) or SSL/TLS certificate configuration, unless they directly enable a material and demonstrable security impact on Survicate systems.
  8. Low-severity issues such as content spoofing or other low-risk issues not creating a material security impact.
  9. Cross-Site Request Forgery (CSRF) vulnerabilities affecting non-sensitive areas only.
  10. Discovery of publicly available information that does not pose a security threat.
  11. Security issues stemming from misconfigured external services or infrastructure not directly controlled by Survicate.
  12. Enumeration of accounts and other resources, unless it leads to a material and demonstrable security impact.
  13. E-mail flooding/bombing.
  14. Vulnerabilities that have already been independently detected by Survicate or previously reported, including reports of the same or substantially similar nature. Similarity includes the use of the same or similar methodology or pattern, or cases where mitigation measures already applied or planned by Survicate would also address the reported Vulnerability.
  15. Circumventing business plan limits defined in Survicate’s pricing and using features without paying for them, including paywall bypass attacks.

§4A. Screening and Rejection of Out-of-Scope or Low-Quality Submissions

A submission is treated as “out of scope” if it concerns a target, issue, or Vulnerability excluded under §4, or otherwise falls outside the Targets defined in §4.

A submission is treated as “low-quality” if it does not meet a minimum quality threshold, including where it: (i) lacks sufficient technical detail to understand or assess the claimed Vulnerability; (ii) does not include clear, accurate, and reproducible steps to reproduce the issue; (iii) does not demonstrate a credible security impact; (iv) consists primarily of raw or unverified automated scanner output without manual analysis or validation by the Participant; or (v) is vague, speculative, duplicative in substance of information already provided in the same or an earlier report, or otherwise fails to provide a usable basis for assessment.

Out-of-scope and low-quality submissions, as defined above, are not eligible for any Reward under §6, regardless of their theoretical severity, and will not be entered into the competitive selection process described in §6.

Survicate may screen and reject an out-of-scope or low-quality submission on a preliminary basis, based on a summary assessment of scope and quality, without conducting the full technical review or investigation otherwise contemplated by §5. Where a submission is rejected on this preliminary basis, Survicate will notify the Participant that the submission has been rejected as out of scope or low-quality and will provide a brief indication of the reason, in place of the full severity and validity assessment described in §5.

Survicate reserves the right, but assumes no obligation, to conduct a fuller review of an out-of-scope or low-quality submission notwithstanding the foregoing, and doing so does not create any right to a Reward or any obligation on Survicate’s part to complete such a review for any other submission.

This section does not limit or narrow the exclusions set out in §4; it clarifies the procedural consequence of a submission falling within those exclusions or otherwise failing to meet the minimum quality threshold described above.

§5. Reporting Procedure (Submission Channel)

Vulnerabilities must be reported via email to bugbounty@survicate.com.

Reports should include detailed information about the Vulnerability, steps to reproduce the issue, and the potential security impact. However, Survicate opposes using discovered Vulnerabilities to violate the privacy of others, obtaining excessive information beyond what is reasonably necessary to document the Vulnerability, performing actions on other persons’ accounts, or engaging in any other activities inconsistent with good security practice or social norms. Reports must include a working proof of concept demonstrating material security impact. Reports that merely describe the absence of a security control (e.g., “no rate limiting”) without demonstrating a concrete, exploitable vulnerability are not eligible. Automated scan output without manual validation is not accepted.

Survicate may request additional information or proof of concept from the Participant in order to validate the Vulnerability.

After conducting an analysis, Survicate will respond to the reporter via email with an assessment of the severity and validity of the Vulnerability, as well as whether a similar Vulnerability has been previously reported. Survicate commits to responding to every submission made through the Program within 30 business days, provided that submissions rejected on a preliminary basis under §4A will instead receive the notice described in that section within the same timeframe.

Participants may submit no more than 3 reports per calendar week. Submissions exceeding this limit may be deprioritized or rejected without review.

Submission order, report quality, completeness, reproducibility, and overall usefulness may affect whether a report is selected for a Reward.

§6. Rewards (Competitive Selection; Limited Pool)

Rewards are determined based on the severity of the Vulnerability and its impact on the security of Survicate systems. Rewards are denominated in USD and payable in USD only. The following reward ranges apply:

  • Critical: up to USD 1,300
  • High: up to USD 550
  • Medium: up to USD 250
  • Low: up to USD 25

Where Polish tax reporting or other mandatory reporting requires amounts to be expressed in PLN, the USD amount shall be converted into PLN using the NBP average exchange rate from the last business day preceding the date on which the taxable income arises or, if required by applicable law, the last business day preceding the payout date.

The amounts are determined based on the severity assessment conducted by Survicate. The assessment is subjective and made at the sole discretion of Survicate. Survicate may refer to CVSS methodology, but reserves the right to make an individual assessment in specific cases.

Participants will only receive a Reward if they are the first to report the Vulnerability, comply with these Terms, and satisfy the payout conditions set out in these Terms. If the Vulnerability has already been reported by another person who received or was selected for a Reward, no additional Reward will be granted.

No Rewards will be issued for vulnerabilities that fall within the out-of-scope exclusions described in §4, or for submissions that are out-of-scope or low-quality under §4A.

The Reward pool is limited, and the order of submissions is taken into account. Due to the competitive nature of the Program, Survicate may, at its sole discretion, reward only selected submissions.

Rewards are payable exclusively via PayPal to the PayPal Account designated by the Participant and accepted by Survicate for payout purposes. Survicate is under no obligation to offer any alternative payout method.

The acceptance, review, validation, remediation, or internal use of a reported Vulnerability does not create any obligation to pay a Reward where payout is legally prohibited, technically unavailable, unsupported by the applicable payment method, or otherwise impossible under these Terms.

A Reward will not be paid unless and until the Participant: (i) completes the payout and tax verification process described in §7; (ii) remains eligible for payout under these Terms; (iii) is not subject to applicable sanctions or other legal, compliance, or payment restrictions; and (iv) is able to receive the Reward through a valid PayPal Account capable of receiving the payout in the relevant jurisdiction.

If any of the above conditions is not met, Survicate may deny, suspend, cancel, or declare forfeited the Reward.

§7. Payout Verification and Tax Settlements

A Participant whose submission has been selected for a potential Reward may be required to complete a payout verification process before any Reward is paid.

For this purpose, Survicate may request, in particular:

  1. the Participant’s full legal name;
  2. residential address;
  3. country of residence and country of tax residence;
  4. date of birth;
  5. tax identification number or other taxpayer identifier required under applicable law;
  6. PayPal e-mail address and other information necessary to verify that the PayPal Account can receive the Reward; and
  7. where applicable, information confirming that the Participant acts on behalf of a company or other entity authorized to receive the Reward.

Survicate will request only the information reasonably necessary to determine whether payout is legally and technically possible and to comply with tax, accounting, fraud prevention, and legal obligations. As a rule, Survicate does not require a copy of an identity document from every Participant. However, Survicate may request additional evidence, including a copy of an identity document or proof of authority to act for an entity, if reasonably necessary to resolve inconsistencies, verify identity, prevent fraud, comply with law, or complete the payout process.

If the Participant fails to provide the requested information within the time indicated by Survicate, provides inaccurate or inconsistent information, fails verification, cannot receive funds through PayPal, or is otherwise ineligible for payout under these Terms, Survicate may deny, suspend, cancel, or forfeit the Reward.

The tax treatment of any Reward shall be determined in accordance with applicable law, taking into account, in particular, the Participant’s status, tax residence, and the documents and information provided by the Participant.

Survicate may withhold, remit, report, or otherwise settle taxes, charges, or mandatory public-law dues connected with the Reward only to the extent required under applicable law.

Where applicable law, a double taxation treaty, or administrative practice requires Survicate to obtain a certificate of tax residence, taxpayer identifier, declaration, or other document before applying a given tax treatment, exemption, or rate, Survicate may condition payout on receipt of such document in form and substance satisfactory to Survicate.

If the Participant does not provide documents or information necessary for proper tax treatment, withholding, reporting, or other compliance obligations, Survicate may apply the treatment required or reasonably justified on the basis of the information available to it, or may refuse payout where payout cannot be lawfully completed.

Any taxes due in the Participant’s jurisdiction of residence or tax residence, to the extent not required to be withheld or settled by Survicate under applicable law, remain the sole responsibility of the Participant.

§8. Responsible Disclosure

Participants must not publicly disclose the Vulnerability without Survicate’s prior written consent.

Any breach of responsible disclosure rules may result in disqualification from the Program, loss of eligibility for a Reward, and potential legal action if damages occur.

§8A. Confidentiality and Non-Use

Any information concerning a reported or discovered Vulnerability, including the existence, nature, technical details, proof of concept, exploit method, related communications, and any non-public information obtained in connection with the Vulnerability, shall be treated as confidential.

The Participant shall not, without Survicate’s prior written consent:

  1. disclose such information to any third party, whether publicly or privately;
  2. publish, distribute, sell, license, transfer, or otherwise make such information available to any other person;
  3. use the Vulnerability or related information for any purpose other than identifying, documenting, and reporting it to Survicate in accordance with these Terms;
  4. retain, reuse, weaponize, exploit, or attempt to exploit the Vulnerability after submitting the report, except to the extent strictly necessary to respond to Survicate’s reasonable requests for validation; or
  5. use any data, access, or information obtained through the Vulnerability for any purpose unrelated to the responsible disclosure of the Vulnerability to Survicate.

The confidentiality and non-use obligations in this section apply regardless of whether the Vulnerability is determined to be valid, in scope, reward-eligible, or rewarded.

Nothing in this section prevents the Participant from making a disclosure where such disclosure is strictly required by applicable law, provided that, where legally permitted, the Participant gives Survicate prior written notice of such requirement.

§9. Legal Considerations

These Terms are the sole rules governing the Program; any promotional materials are for reference only.

Survicate reserves the right to modify, suspend, or terminate the Program at any time without prior notice.

Participation in the Program does not establish an employment, partnership, agency, mandate, or any similar relationship between the Participant and Survicate.

Any matters and disputes arising from participation in the Program shall be governed by the laws of Poland.

The Program will run from October 15, 2024, until terminated by the Organizer.

These Revised Terms of the Survicate S.A. Bug Bounty Program are binding and effective as of 14.07.2026.

Information on Personal Data Processing for a Person Participating in the Bug Bounty Program

The controller of your personal data is Survicate S.A. (full details as in §2 above). A Data Protection Officer has been appointed at Survicate S.A. and can be contacted at: gdpr@survicate.com.

Purpose of processing

Your personal data are processed for the following purposes:

  1. receiving, reviewing, assessing, and investigating vulnerability reports;
  2. communicating with you in relation to your report;
  3. administering the Program;
  4. determining whether a report is eligible for a Reward;
  5. where applicable, conducting payout, tax, fraud-prevention, sanctions, and compliance verification; and
  6. paying a Reward and fulfilling related legal, accounting, and tax obligations.

Legal basis

Your personal data are processed on the basis of:

  1. Article 6(1)(b) GDPR – to take steps at your request and to perform the Program terms, including handling your report and, where applicable, arranging payout;
  2. Article 6(1)(c) GDPR – to comply with legal obligations binding on Survicate, including tax, accounting, and compliance obligations;
  3. Article 6(1)(f) GDPR – for Survicate’s legitimate interests consisting in improving the security of its systems and services, preventing abuse and fraud, defending claims, and administering the Program.

Categories of personal data

Depending on the stage of your participation, Survicate may process:

  1. identification and contact data, such as your name, email address, and country of residence;
  2. information contained in your vulnerability report and related correspondence;
  3. technical data necessary to review and verify your report;
  4. if your report is selected for possible Reward, additional payout and tax data, such as your full legal name, residential address, date of birth, country of tax residence, taxpayer identifier, PayPal e-mail address, and information on whether you act on your own behalf or for an entity;
  5. in exceptional cases only, additional evidence reasonably necessary to verify payout eligibility or prevent fraud, such as proof of authority to act for a legal entity or a copy of an identity document.

Data recipients

Your personal data may be disclosed to:

  1. authorized Survicate personnel involved in handling vulnerability reports, security assessment, finance, legal, compliance, or Program administration;
  2. IT service providers, hosting providers, communication service providers, legal advisers, auditors, or other professional advisers bound by confidentiality obligations;
  3. payment service providers, including PayPal, where necessary to complete or attempt a payout;
  4. public authorities or other recipients where disclosure is required by law.

Transfers outside the EEA

Your personal data may be transferred outside the European Economic Area where necessary for the use of service providers or payment providers, including PayPal, provided that appropriate safeguards required by applicable data protection law are applied.

Retention period

Your personal data will be retained:

  1. for as long as necessary to review and handle your report and administer the Program;
  2. if a report is reward-eligible or a Reward is paid, for as long as necessary to complete payout and comply with legal, accounting, and tax obligations;
  3. thereafter, for the period necessary to defend or pursue legal claims and to demonstrate compliance with legal obligations.

Your rights

Subject to the conditions laid down in the GDPR, you have the right to:

  • access your personal data;
  • rectify your personal data;
  • erase your personal data;
  • restrict processing;
  • object to processing based on Article 6(1)(f) GDPR;
  • data portability, where applicable;
  • lodge a complaint with the competent supervisory authority, in particular the President of the Personal Data Protection Office (UODO).

Contact

You may contact Survicate regarding personal data processing at: gdpr@survicate.com or at Survicate S.A., ul. Zamiany 8 LU2, 02–786 Warsaw, Poland.

Profiling

Your personal data are not subject to automated decision-making, including profiling, within the meaning of Article 22 GDPR.