Bug Bounty Program

    At Pokee AI, security is a top priority. We value the work of security researchers who help us keep our platform and users safe. If you discover a security vulnerability, we want to hear from you.

    Reward Tiers

    Bounties are awarded based on the severity of the verified vulnerability. All reports are evaluated on a case-by-case basis.

    Low Severity
    2,000 Pokee API credits

    Minor issues with limited impact, such as non-sensitive information disclosure, low-risk misconfigurations, or UI-level bugs with minimal security implications.

    Medium Severity
    5,000 Pokee API credits

    Issues that could lead to limited data exposure, privilege escalation in restricted contexts, or meaningful bypasses of non-critical security controls.

    Critical Severity
    10,000 Pokee API credits

    Severe vulnerabilities such as remote code execution, authentication bypass, SQL injection, access to sensitive user data, or full account takeover.

    Pokee AI reserves the right to determine the final severity classification and reward amount for all reported vulnerabilities. Exceptional findings may receive higher rewards at our discretion.

    Scope

    In Scope

    • pokee.ai — main website and web application
    • api.pokee.ai — public-facing API endpoints
    • Authentication and authorization mechanisms
    • Payment and billing flows
    • User data handling and storage
    • PokeeClaw environment isolation

    Out of Scope

    • Third-party services and integrations not operated by Pokee
    • Social engineering, phishing, or physical attacks against Pokee employees
    • Denial-of-service (DoS/DDoS) attacks
    • Spam or rate-limiting issues without a security impact
    • Vulnerabilities in outdated browsers or platforms we do not support
    • Reports from automated scanners without a demonstrated proof of concept
    • Clickjacking on pages with no sensitive actions
    • Missing security headers that do not lead to a demonstrable exploit
    • Issues that require a user to install or run a third-party Skill from the Skill Marketplace, where the impact is limited to that user's own data and privileges — including a Skill exfiltrating that user's own files or credentials — see below

    Skill Marketplace & Third-Party Skills

    Skills published to the Skill Marketplace are written by third parties, not by Pokee AI. Installing a Skill lets it act inside your own workspace on your behalf, and that decision — as with any third-party extension or package — rests with the user who installs it. We review submissions and apply confinement controls to limit what a malicious Skill can reach, but no review process can anticipate every possible attack, and we make no representation that any given Skill is safe.

    Reports whose exploit path requires a user to install or run a Skill, and whose impact is limited to the data and privileges that user already holds, are therefore not eligible for a reward. This includes a malicious Skill reading, modifying, or exfiltrating to an external destination the installing user's own files, workspace contents, chat history, or connected-account credentials. A Skill you install acts with your access, and demonstrating that it can send your own data somewhere is a property of that decision rather than a vulnerability in Pokee AI.

    This exclusion is about user choice, not about our confinement boundaries. Where a Skill reaches beyond the installing user's own access, we want to hear about it. The following remain fully in scope and eligible:

    • A Skill escaping its sandbox or breaking out of the PokeeClaw container
    • A Skill reaching another user's or another tenant's data, sessions, or credentials
    • A Skill obtaining Pokee AI platform secrets or infrastructure credentials — service tokens, model-provider keys, or internal endpoints that no Skill should be able to reach
    • Bypassing Marketplace publishing, review, or listing-integrity controls — for example, publishing under another party's identity, or altering a listing after review
    • Any flaw that allows a Skill to be installed, updated, or executed without the user's action or consent

    What to Report

    We are interested in vulnerabilities that have a real security impact. Examples include, but are not limited to:

    • Remote code execution (RCE)
    • SQL injection, NoSQL injection, or command injection
    • Cross-site scripting (XSS) with demonstrable impact
    • Cross-site request forgery (CSRF) on sensitive actions
    • Authentication or session management flaws (e.g., account takeover, session fixation)
    • Insecure direct object references (IDOR) leading to unauthorized data access
    • Server-side request forgery (SSRF) with access to internal resources
    • Privilege escalation between users or roles
    • Exposure of sensitive data (API keys, credentials, PII)
    • Sandbox escape or container breakout

    How to Report

    Important: Bug bounty reports must be sent only to support@pokee.ai. Sending a bug report to any other Pokee AI email address will result in an immediate ban from the bug bounty program.

    Send your report to support@pokee.ai with "Bug Bounty" in the subject line.

    Please include the following in your report:

    1. Description — A clear summary of the vulnerability and its potential impact.
    2. Steps to reproduce — Detailed, step-by-step instructions that allow us to reliably reproduce the issue.
    3. Proof of concept — Screenshots, screen recordings, HTTP request/response logs, or working exploit code.
    4. Affected asset — The URL, endpoint, or component where the vulnerability exists.
    5. Suggested severity — Your assessment of the impact (Low, Medium, or Critical).
    6. Your contact info — How we can reach you for follow-up questions.
    7. HackerOne profile (optional) — Include your HackerOne username or profile URL. Reports with a profile may be reviewed sooner.

    On AI-Generated Bug Bounty Reports

    We acknowledge and understand the use of AI in preparing bug bounty findings. However, we prefer concise, well-formatted reports that clearly explain the vulnerability, its impact, and how to reproduce it. Low-effort dumps of AI-generated output will be deprioritized or ignored.

    Our Process

    1

    Initial Review

    We will respond only to reports that describe vulnerabilities eligible for a reward.

    2

    Verification

    Our security team will review and attempt to reproduce the issue. We may reach out for additional information. Please allow us reasonable time to investigate and verify.

    3

    Severity Assessment

    We will classify the severity based on factors including exploitability, impact, and affected scope. We do our best to evaluate every report fairly, and we welcome your input, but the final determination of severity and reward amount rests with Pokee AI.

    4

    Remediation & Reward

    Once the vulnerability is confirmed and patched, we will apply the bounty credits to your Pokee API account.

    Reward Terms

    Pokee API Credit Rewards

    All rewards are issued as Pokee API credits to the eligible reporter's Pokee API account. Rewards are not cash payments and cannot be exchanged for cash or transferred to another account.

    • Severity and rewards are determined solely by Pokee AI. We retain all rights to assess the severity of a reported issue and to set the corresponding reward amount. These determinations are final and not subject to negotiation.
    • We cannot share our reasoning. Due to company policy, we are unable to disclose the internal details, criteria, or reasoning behind our severity classifications and reward decisions.
    • No response means no qualifying bug. If you do not hear back from us regarding a report, it means the submission was not deemed a qualifying vulnerability under this program and no reward will be issued. We are not able to provide individual feedback on every report.

    Rules of Engagement

    • Do not access, modify, or delete data belonging to other users. Use your own test accounts only.
    • Do not perform actions that could degrade service availability (e.g., DoS, brute force, excessive scanning).
    • Do not publicly disclose a vulnerability before we have had a reasonable opportunity to address it.
    • Act in good faith. Research should be conducted in a way that avoids privacy violations, data destruction, or service interruption.
    • One report per vulnerability. If you find multiple instances of the same class of bug, please group them into a single report.
    • You must be the first to report the vulnerability to be eligible for a reward.
    • Send reports only to support@pokee.ai. Sending a bug report to any other Pokee AI email address will result in an immediate ban from the bug bounty program.
    • Pokee AI employees, contractors, and their immediate family members are not eligible.

    Safe Harbor

    We consider security research conducted in accordance with this policy to be authorized. We will not pursue legal action against researchers who discover and report vulnerabilities responsibly and in compliance with the rules above. If legal action is initiated by a third party against you for activities conducted in accordance with this policy, we will make it known that your actions were authorized by Pokee AI.

    Found something?

    Help us keep Pokee AI safe. Report a vulnerability today.

    Add your HackerOne profile to help us review your report sooner.