bug bounty
Hack the system
We believe security is a community effort. moood invites researchers to responsibly disclose vulnerabilities in exchange for recognition and financial rewards that grow as we grow.
Overview
Responsible disclosure at moood
We're a startup. we can't compete with big tech bounties yet but we promise transparency, respect and retroactive rewards for those who help us early.
bounty tiers
Rewards that scale with us
Payouts scale with our revenue. select a stage to see reward ranges.
scope
What's in bounds
Review what's in bounds before testing. out-of-scope reports may still be acknowledged but won't qualify for rewards.
In scope
- app.moood.tech (web application)
- moood.tech (marketing site)
- API endpoints
- authentication & session management
- blind relay architecture
- mood data access controls
- cloud functions
- mobile apps (iOS & Android)
Out of scope
- third-party services (Firebase, Cloudflare)
- denial of service (DoS/DDoS)
- social engineering or phishing
- physical security
- automated scanning without approval
- attacks against employees or users
- staging/dev environments
rules of engagement
How to test responsibly
# safe harbor policy we consider security research conducted in accordance with this policy to be: → authorized → lawful → helpful → protected we will not pursue civil or criminal action against researchers who discover and report vulnerabilities in good faith and in compliance with this policy. if you are uncertain whether your research is consistent with this policy, reach out first. we're happy to clarify.
hall of fame
Researchers who made moood safer
Every researcher with a valid finding earns their place here — these individuals helped make moood safer for everyone.
report a vulnerability
How to reach us
To report a security vulnerability, please open a support ticket. include as much detail as possible — full URL, parameters, payloads, screenshots, and tools used.
Select "other" as the category and include "security" in the subject line so we can prioritise your report.