Bug Bounty Program
Version 1.0 of 22 Aug 2026
Security is core to everything we do at wservices. We invite security researchers to responsibly discover and report vulnerabilities in our infrastructure and web interface (wcenter). Verified, previously-unknown reports are rewarded.
Scope
In scope
- wservices.ch and its public web services
- The wcenter control panel
- djangoeurope.com hosting infrastructure
- Our mail and DNS services
Out of scope
- Third-party services and sub-processors
- Customer websites and applications hosted on our platform (report those to the site owner)
- Social engineering and phishing of our staff or customers
- Physical attacks against data centers or offices
- Denial-of-service (DoS/DDoS) and volumetric attacks
- Automated scanner output without a working proof-of-concept
Informational findings we do not accept
Findings without a demonstrated security impact are out of scope and will not be rewarded. Please do not report the following:
- Missing, weak or unset HTTP security headers (Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, X-XSS-Protection and similar)
- Cookie attribute findings (Secure, HttpOnly, SameSite) without a demonstrated exploit
- SSL/TLS configuration recommendations (cipher suites, protocol versions, certificate pinning, CAA records, HSTS preload) without a practical exploit
- SPF, DKIM or DMARC issues, email spoofing and other mail-hardening recommendations
- Clickjacking, logout CSRF, self-XSS and issues that require unlikely user interaction with no demonstrated impact
- Open redirects, mixed content, CORS misconfigurations and host-header issues without proven data theft or account takeover
- Missing rate limiting, credential stuffing or username/email enumeration without a working bypass of existing controls
- Information disclosure with no security impact (software versions, server banners, public directory listings, verbose errors that do not leak secrets)
- Best-practice or hardening recommendations, theoretical issues, and findings that only affect outdated browsers
The Process
- 1
Registration
Register your intent by e-mailing security@wservices.ch with your name or handle and a short description of your research focus. You receive a confirmation and a reporting reference.
- 2
Testing
Test only in-scope targets. Never access, modify or destroy data that is not yours. Use a dedicated test account where possible. No DoS, no spam, no automated mass-scanning.
- 3
Delivery (Report Submission)
Submit a detailed report to security@wservices.ch including the affected target/URL, vulnerability type, step-by-step reproduction, a working proof-of-concept, an impact assessment and any suggested remediation. Encrypt sensitive reports with our PGP key on request.
- 4
Triage & Validation
We acknowledge your report within 3 business days and validate it. We may contact you for clarification during this phase.
- 5
Resolution
We fix confirmed issues and keep you updated on the progress. Please allow reasonable time for remediation before any public disclosure (coordinated disclosure, 90 days recommended).
- 6
Reward
Once the issue is fixed and verified, we grant the applicable reward (see below).
Rewards
Rewards are granted at wservices’ discretion based on severity, impact and report quality. Duplicates are awarded to the first reporter only.
| Severity / Finding | Reward |
|---|---|
Low severity Limited impact, no account takeover. Examples: XSS on a public marketing page, CSRF on a low-impact setting, open redirect without stealing a session, disclosure of non-sensitive configuration. | One year of a free djangoeurope X10 plan. |
Medium severity Access to a single account or limited customer data. Examples: session-stealing XSS in wcenter, IDOR on another customer’s tickets, CSRF that changes email forwarding or a password, SSRF to an internal HTTP service without credentials. | One year of a free djangoeurope X12 plan. |
High severity Cross-customer data access, admin-level control, or local root from an unprivileged SSH account after the 3-day CVE window. Examples: SQL injection on customer databases, authentication bypass or account takeover of arbitrary users, unauthorized wcenter admin, access to backups or mailboxes of other customers, a working local root exploit from an unprivileged SSH user when the CVE has been unpatched for more than 3 days. | €500, plus one year of a free djangoeurope X14 plan. |
Critical — Remote Code Execution as root (root RCE) Remote code execution as root on in-scope production systems, without needing an existing SSH login. Examples: unauthenticated remote root RCE on the hosting fleet, wcenter host or mail/DNS servers; an exploit chain that yields a remote root shell. Local root from an unprivileged SSH account is High, not Critical. | €1,000, plus one year of a free djangoeurope X16 plan. |
Additionally, every valid, previously-unknown finding in the Low, Medium, High or Critical category receives public recognition on our Security Hall of Fame.
Rules & Safe Harbor
- Follow responsible, coordinated disclosure; do not publicly disclose a finding before we have resolved it and agreed on disclosure.
- Do not violate the privacy of our users, degrade our services, or destroy data.
- Submit only issues with a working proof-of-concept and a clear security impact. Informational findings, missing headers and scanner-only reports are not eligible for a reward.
- Gaining root privileges from an unprivileged SSH user (a working local root exploit) based on a known bug does not count for the first 3 days after the CVE has been released. After those 3 days, if the host is still unpatched, it is High severity — not Critical.
- Comply with Swiss law and these program rules at all times.
- Good-faith security research conducted under these rules will not lead to legal action from wservices.