> ## Documentation Index
> Fetch the complete documentation index at: https://developer.bron.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Bug Bounty

> Responsible vulnerability disclosure program — Bron Foundation

Bron runs a **Bug Bounty Program** to encourage responsible disclosure of security vulnerabilities. We welcome researchers to report issues in our Web & API, mobile and desktop apps, smart contracts, and MPC cryptography library.

## Program overview

* **Policy**: [Responsible Vulnerability Disclosure Policy](https://bugbounty.bron.org/policy) — scope, testing rules, and legal notice
* **Rewards**: [Reward tables](https://bugbounty.bron.org/rewards) — CVSS v4.0–based ranges and payout conditions
* **Report**: [Submit a report](https://bugbounty.bron.org/report) — format, reproduction steps, and PoC requirements
* **Hall of Fame**: [Acknowledgments](https://bugbounty.bron.org/hall-of-fame) to researchers who help improve our security

## MPC library (bron-crypto)

The open source **bron-crypto** MPC library is in scope. See [github.com/bronlabs/bron-crypto](https://github.com/bronlabs/bron-crypto) and its [SECURITY.md](https://github.com/bronlabs/bron-crypto/blob/master/SECURITY.md) for scope and reporting details.

## Contact

Submit reports to **[bugbounty@bron.org](mailto:bugbounty@bron.org)**.\
**SLA**: Acknowledgment within 3 business days; initial triage within 10 business days.

***

<Card title="Bug Bounty Program" icon="external-link" horizontal="true" href="https://bugbounty.bron.org">
  More about our Bug Bounty program — policy, rewards, reporting, and Hall of Fame — on the **Bug Bounty** site.
</Card>
