← Home/Security/Bug Bounty

Help keep VGSpartans safe.

A private sign-up program for finding security problems before anyone else does. Whatever you report stays between you and our team. Sign up to take part, or if you already spotted something, send it straight to us.

Private reports only
vgspartans.org/bug-bounty
Join the program
Private sign-up · we'll be in touch
Your details
ConfidentialGood faith
Part 1 · Take part

Sign up for the program.

Want to help look for security issues? Add your name and we'll reach out with how to take part. Nothing about scope is posted here; we share that one to one once you're in.

Email us to join

Send your name, say whether you're a Vista Grande student, staff, or an outside researcher, and promise to keep anything you find quiet until it's fixed. Give us a personal email to set the account up on, not a school one.

Sign me up

Why sign up first?

So we can tell you yes, you're cleared to look, and so reports come from people we know. It keeps everyone out of trouble.

1

You ask

Your name, a personal email, and a quick promise to keep things private.

2

We set you up

We create your access, write down exactly what you may test, and email you.

3

You're in

Your own console: your scope, the rules, any tasks, and a private line to us.

A personal email

Not a school one. Bug bounty access is its own account, kept separate on purpose, so when it ends nothing else about you ends with it.

Applies to students and staff too

It runs out on its own

Access is time-boxed, never longer than 62 days at a time. We'll email you a week and again three days before it ends.

After that you can't sign in until we renew it

Two-factor is required

You'll set one up before you can get in: an authenticator app, a passkey, or a security key. There's no way around it.

A passkey or security key is strongest
Part 2 · Already found something?

Three private ways to send it.

You don't need to sign up first. If you came across a security problem, even by accident, tell us privately through any of these and we'll take it from there.

GitHub advisory

Open a private security advisory on the repo. Best if you have a GitHub account and repro steps to share.

Open GitHub's Security tab Private · coordinated disclosure

Send it in the app

Sign in and file it through the report form, tagged as a security concern. Attach a proof-of-concept or screenshots, up to 25 MB.

Open the report form Signed-in · attach files · lands in our console
Keep it private, and stop at the first find.Tell us what you saw and where. Keep it out of public view, and once you've found one issue, leave it with us instead of digging for more.

What to include

Keep it short, we'll follow up with questions.

What you sawWhere (a page or link)A screenshot, if you have one

What happens next

A person reads it, and we try to reply within a week. We fix the issue and put your name on it if you want the credit. We can't offer cash, but the credit is yours.

The short version

Be kind, keep it private.

Please do

Report it privatelyUse only your own accountGive us time to fix it

Please don't

Post it publiclyPoke at other people's accountsKeep digging after the first find