Responsible disclosure
Help us keep TinyX secure.
TinyX is not a formal public bug bounty with fixed payouts. We still welcome good-faith reports — and we treat them with urgency, respect, and credit when you want it.
How to report
Email support@tinyx.co with a clear write-up. Prefer PGP? Use the key linked from security.txt.
Include in your report
- A clear description of the vulnerability
- Steps to reproduce (more detail means faster triage)
- Potential impact as you understand it
- Your contact information so we can follow up
What we promise
Straight talk from the people who ship the code.
Scope (summary)
High-level only — the authoritative list lives on tinyx.co/security.
In scope
- Auth / authorisation bypasses
- XSS, injection, SSRF
- Encryption implementation flaws
- Data exposure or leakage
- Privilege escalation across tiers or roles
- Webhook / API abuse, session issues
- Bypasses of link expiry, download limits, or access controls
Out of scope
- Social engineering or phishing our team
- DoS / DDoS testing on production
- Issues in third-party services (report to them)
- Missing headers without a demonstrable exploit
- Self-XSS or physical-access requirements
- Scanner output without a verified exploit
Full scope, testing rules, and stack details: https://tinyx.co/security
Rewards
There is no fixed bounty table. When we reward a finding, it is discretionary — cash, a lifetime Pro/Max account, a public shoutout, or a mix — depending on severity and impact.
What we can guarantee
If you find something real and report it responsibly, we will not ignore you, and we will not be cheap about recognising the work.
Rules of engagement
- Use your own test accounts only — never other users’ data
- Do not disrupt the service (no production load tests, no deleting others’ files)
- Coordinated disclosure: give us reasonable time to patch before going public
- One vulnerability per report
Researchers we thank
Public credit for people who reported issues in good faith. This wall grows as TinyX credits more researchers.
Huzaifa
Muhammad Huzefa
Asfahan
achilleus
Prefer to stay anonymous? Say so when you report — we will honour that.
Found something?
Email us. Clear description, repro steps, impact, and a way to reach you.