Last updated: February 5, 2025
At Minut, we are committed to ensuring the security and privacy of our devices and services. We believe in the power of collaboration with the security research community to identify and address potential vulnerabilities. Our Bug Bounty Program is designed to reward security researchers for their efforts in discovering and responsibly reporting security issues.
This program covers all our devices, mobile and web applications, and cloud services unless explicitly excluded below.
Specifically, the scope includes:
The following devices are excluded:
To participate in our Bug Bounty Program, you must:
To submit a vulnerability report:
Submit your report only to the address above, not to any other support or employee addresses. Failure to comply will result in your email address being banned and your report disregarded.
Rewards are based on the severity and impact of the reported issue. We reserve the right to decide the size of the reward (if any). Our general reward structure is as follows:
You’ll need to submit an invoice to receive the payment. The invoice has to meet all legal requirements for Minut’s accounting purposes. We accept payment via Paypal or bank transfer.
We do not currently support payment via Western Union, crypto currency or other alternative payment mechanisms.
You’re responsible for paying applicable taxes in your jurisdiction. The total amount paid should match the reward determined by Minut.
Please note that the bug bounty program is voluntary. While striving to respond quickly and pay fair rewards, Minut is not obligated to following specific timelines or paying you anything. Threatening us because we don’t share your view of the report will get you banned from the program.
We will not pursue legal action against researchers who:
The following are not eligible for rewards:
We aim to respond to all submissions within 5 business days. Our typical timeline for addressing issues is:
Please don’t send automated, scheduled or repeated requests for updates after receiving confirmation that we have received the report.
For questions about this program, please get in touch with our security team at vulnreports@minut.com.
We reserve the right to update this policy at any time. Any changes will be posted on this page with an updated revision date.