Florida Proxies logo
Security

Responsible disclosure & bug bounty policy

Please tell us about any vulnerability you find in Florida Proxies. This page explains what is in scope, what we pay for and what we do not, and how to report, so nobody on either side is surprised.

Scope

In scope

  • This website, floridaproxies.com
  • The dashboard customers sign in to, along with its API
  • Handling of proxy credentials, API keys and rotation links inside the dashboard

Out of scope

  • The proxy gateways and modem hosts, plus the mobile carrier networks behind them
  • Third-party providers: email providers, Cloudflare, Telegram, payment processors
  • Marketing assets served from legacy CDN paths
  • Any account or customer data that belongs to another person

What we pay

What we reward is demonstrated impact on our systems or on our customers. Amounts are in USD.

Critical
$100 – $250
  • Remote code execution on our servers
  • SQL injection that can read or change customer data
  • Bypassing authentication to enter any account without its credentials
  • Balance or payment manipulation — getting proxies, credit or refunds for free
  • Exposing other customers' personal data or proxy credentials in bulk
High
$50 – $100
  • Access to read or change another customer's orders, proxies or account details (IDOR)
  • Stored cross-site scripting running in the session of another customer or an admin
  • A customer account escalating its privileges to admin functions
  • Server-side request forgery reaching internal services
  • Taking the API key, rotation link or session of another account
Medium
$20 – $50
  • Cross-site request forgery that triggers an account state change
  • Reflected cross-site scripting needing the victim to click a link
  • A rate-limit bypass resulting in a demonstrated account takeover
  • Pricing or business-logic mistakes shown to have a financial impact
Low / Informational
$0

Acknowledged, fixed if warranted, yet not paid. Check the full list below before writing your report.

What we do not pay for

These are accepted at Low or Informational, never higher. Each one is read and anything worth fixing gets fixed, but no bounty is issued, even if the report carries a Critical or High label.

  • A login session that survives a password reset, a password change or a logout until its token expires
  • Absent or “weak” security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy) lacking a working exploit
  • Clickjacking of pages that have no sensitive action
  • Attribute settings on cookies that are not session cookies
  • Username or email enumeration, timing- and error-message-based included
  • Login, forgot-password or rate-limit findings that stop short of a demonstrated account takeover
  • Views about password policy: complexity, length, no forced rotation, common-password lists
  • 2FA that is optional, or no two-factor authentication offered
  • XSS that only fires in the attacker's own session, or Self-XSS
  • CSRF on non-sensitive forms such as login, logout or language
  • Open redirects with no token or credential leakage
  • Server banners, software versions, stack traces or paths disclosed without sensitive data
  • SPF, DKIM or DMARC configuration reports
  • Results from automated scanners that come without a proof of concept
  • Brute force, denial of service, resource exhaustion or any test that creates load
  • Social engineering or phishing against our customers or staff, and physical attacks
  • Issues found in the third parties we work with: payment processors, Telegram, Cloudflare, email providers
  • Outdated libraries, unless there is a working exploit against our deployment
  • Anything that only works from a compromised device, a rooted phone or a man-in-the-middle position
  • Best-practice suggestions, theoretical risks, and repeats of issues we already know

How to report

Email [email protected] with the subject Security report. Your report should include the affected URL, exact reproduction steps, the account you used and a proof of concept. Expect an acknowledgment within 5 business days and a severity decision within 10 business days.

Machine-readable contact details are at /.well-known/security.txt.

Send a report

Policy last updated 2026-10-10.

Rules of engagement

  1. First valid report wins. Duplicate reports, and reports on issues already known to us, are not paid. A single root cause earns one payment, whatever the endpoint count.
  2. Prove it, then stop. Access only your own accounts and data. When a test would reveal someone else's data, stop at your first proof and report — never pivot, download or persist.
  3. Do not degrade the service. Do not run load tests, automated fuzzing at volume, or any test against proxy gateways, modem hosts or carrier networks. Those are out of scope entirely.
  4. Give us time. Please wait to publish until we have fixed the issue and 30 days have passed. We will let you know when a fix goes live.
  5. Severity is ours to set. Using the Bugcrowd Vulnerability Rating Taxonomy as the reference, we rate the impact on our own systems. Within the ranges above, payment amounts are at our discretion, paid by PayPal or USDT.
Safe harbour. Research that follows these rules is authorised. We will not pursue legal action against you for good-faith testing that stays within scope, and we ask you to show us the same good faith: no extortion, no threats of disclosure and no “pay first, details later”.