Bug Bounty Program

Security is core to everything we do at wservices. We invite security researchers to responsibly discover and report vulnerabilities in our infrastructure and web interface (wcenter). Verified, previously-unknown reports are rewarded.

Scope

In scope

  • wservices.ch and its public web services
  • The wcenter control panel
  • djangoeurope.com hosting infrastructure
  • Our mail and DNS services

Out of scope

  • Third-party services and sub-processors
  • Social engineering and phishing of our staff or customers
  • Physical attacks against data centers or offices
  • Denial-of-service (DoS/DDoS) and volumetric attacks
  • Automated scanner output without a working proof-of-concept

The Process

  1. 1

    Registration

    Register your intent by e-mailing security@wservices.ch with your name or handle and a short description of your research focus. You receive a confirmation and a reporting reference.

  2. 2

    Testing

    Test only in-scope targets. Never access, modify or destroy data that is not yours. Use a dedicated test account where possible. No DoS, no spam, no automated mass-scanning.

  3. 3

    Delivery (Report Submission)

    Submit a detailed report to security@wservices.ch including the affected target/URL, vulnerability type, step-by-step reproduction, a working proof-of-concept, an impact assessment and any suggested remediation. Encrypt sensitive reports with our PGP key on request.

  4. 4

    Triage & Validation

    We acknowledge your report within 3 business days and validate it. We may contact you for clarification during this phase.

  5. 5

    Resolution

    We fix confirmed issues and keep you updated on the progress. Please allow reasonable time for remediation before any public disclosure (coordinated disclosure, 90 days recommended).

  6. 6

    Reward

    Once the issue is fixed and verified, we grant the applicable reward (see below).

Rewards

Rewards are granted at wservices’ discretion based on severity, impact and report quality. Duplicates are awarded to the first reporter only.

Severity / FindingReward
Valid report (Hall of Fame)Public recognition on our Security Hall of Fame for every valid, previously-unknown report.
Low / Medium severityOne year of a free Starter, Growth or Business plan (depending on severity/impact), or a free djangoeurope hosting plan for one year.
High severityA free djangoeurope hosting plan for one year, plus Hall of Fame.
Critical — Remote Code Execution as root (root RCE)Top reward of $500, plus Hall of Fame and a free hosting plan.

Rules & Safe Harbor

Contact

Please send all reports and registration requests to our security team.

security@wservices.ch