Bug Bounty Program

Version 1.0 of 22 Aug 2026

Security is core to everything we do at wservices. We invite security researchers to responsibly discover and report vulnerabilities in our infrastructure and web interface (wcenter). Verified, previously-unknown reports are rewarded.

Scope

In scope

  • wservices.ch and its public web services
  • The wcenter control panel
  • djangoeurope.com hosting infrastructure
  • Our mail and DNS services

Out of scope

  • Third-party services and sub-processors
  • Customer websites and applications hosted on our platform (report those to the site owner)
  • Social engineering and phishing of our staff or customers
  • Physical attacks against data centers or offices
  • Denial-of-service (DoS/DDoS) and volumetric attacks
  • Automated scanner output without a working proof-of-concept

Informational findings we do not accept

Findings without a demonstrated security impact are out of scope and will not be rewarded. Please do not report the following:

  • Missing, weak or unset HTTP security headers (Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection and similar)
  • Cookie attribute findings (Secure, HttpOnly, SameSite) without a demonstrated exploit
  • SSL/TLS configuration recommendations (cipher suites, protocol versions, certificate pinning, CAA records, HSTS preload) without a practical exploit
  • SPF, DKIM or DMARC issues, email spoofing and other mail-hardening recommendations
  • Clickjacking, logout CSRF, self-XSS and issues that require unlikely user interaction with no demonstrated impact
  • Open redirects, mixed content, CORS misconfigurations and host-header issues without proven data theft or account takeover
  • Missing rate limiting, credential stuffing or username/email enumeration without a working bypass of existing controls
  • Information disclosure with no security impact (software versions, server banners, public directory listings, verbose errors that do not leak secrets)
  • Best-practice or hardening recommendations, theoretical issues, and findings that only affect outdated browsers

The Process

  1. 1

    Registration

    Register your intent by e-mailing security@wservices.ch with your name or handle and a short description of your research focus. You receive a confirmation and a reporting reference.

  2. 2

    Testing

    Test only in-scope targets. Never access, modify or destroy data that is not yours. Use a dedicated test account where possible. No DoS, no spam, no automated mass-scanning.

  3. 3

    Delivery (Report Submission)

    Submit a detailed report to security@wservices.ch including the affected target/URL, vulnerability type, step-by-step reproduction, a working proof-of-concept, an impact assessment and any suggested remediation. Encrypt sensitive reports with our PGP key on request.

  4. 4

    Triage & Validation

    We acknowledge your report within 3 business days and validate it. We may contact you for clarification during this phase.

  5. 5

    Resolution

    We fix confirmed issues and keep you updated on the progress. Please allow reasonable time for remediation before any public disclosure (coordinated disclosure, 90 days recommended).

  6. 6

    Reward

    Once the issue is fixed and verified, we grant the applicable reward (see below).

Rewards

Rewards are granted at wservices’ discretion based on severity, impact and report quality. Duplicates are awarded to the first reporter only.

Severity / FindingReward
Low severity

Limited impact, no account takeover. Examples: XSS on a public marketing page, CSRF on a low-impact setting, open redirect without stealing a session, disclosure of non-sensitive configuration.

One year of a free djangoeurope X10 plan.
Medium severity

Access to a single account or limited customer data. Examples: session-stealing XSS in wcenter, IDOR on another customer’s tickets, CSRF that changes email forwarding or a password, SSRF to an internal HTTP service without credentials.

One year of a free djangoeurope X12 plan.
High severity

Cross-customer data access, admin-level control, or local root from an unprivileged SSH account after the 3-day CVE window. Examples: SQL injection on customer databases, authentication bypass or account takeover of arbitrary users, unauthorized wcenter admin, access to backups or mailboxes of other customers, a working local root exploit from an unprivileged SSH user when the CVE has been unpatched for more than 3 days.

€500, plus one year of a free djangoeurope X14 plan.
Critical — Remote Code Execution as root (root RCE)

Remote code execution as root on in-scope production systems, without needing an existing SSH login. Examples: unauthenticated remote root RCE on the hosting fleet, wcenter host or mail/DNS servers; an exploit chain that yields a remote root shell. Local root from an unprivileged SSH account is High, not Critical.

€1,000, plus one year of a free djangoeurope X16 plan.

Additionally, every valid, previously-unknown finding in the Low, Medium, High or Critical category receives public recognition on our Security Hall of Fame.

Rules & Safe Harbor

Contact

Please send all reports and registration requests to our security team.

security@wservices.ch