TPP
Bounty program

Report a vulnerability

If you find a security issue in a system we operate, tell us. We read every good-faith report. A reward is our decision, and we pay it only after we confirm the issue.

Developer resources

Rewards

The figures are upper bounds, not a quote. We set the amount after we reproduce the issue. We pay the first valid report. We may pay less, or nothing, when the impact is narrow, the report is incomplete, or we already knew.

  • Critical

    Up to €3,000

    Remote code execution, or a bypass that exposes other customers’ data without their credentials.

  • High

    Up to €1,000

    Access to another customer’s data while signed in, or a step up to an administrator.

  • Medium

    Up to €500

    Cross-site scripting or cross-site request forgery on an action that changes data, when the impact is realistic.

  • Low

    Up to €100

    A small information leak or an open redirect, when you can show the impact.

Notes without a demonstrated impact — missing headers, scanner output, best-practice comments — are welcome and are not paid. We pay in euros or USDT, after we accept the report, usually within 30 days.

What you can test

Only systems we operate, and only with an account you own. If a test would expose or change someone else’s data, stop and describe what you already saw.

  • The public site, www.thepowerplugin.com.
  • The operations app at app.thepowerplugin.com, with your own account.
  • The rewards API, hosted storefront and MCP endpoint on hosts we operate, including the documented sandbox.

How to test

  • Go only as far as you need to show the impact.
  • Do not degrade the service. No denial of service, flooding or password guessing.
  • Do not phish staff, customers or suppliers, and do not attempt physical access.
  • Do not access, change or download data that is not yours. Your own account is enough to demonstrate an issue.
  • Wait 90 days from your report before you publish anything, unless we agree to a shorter window.
  • Send one issue per report.

Out of scope

  • Denial of service, and automated scanning that puts load on the service.
  • Social engineering and physical attacks.
  • Third parties we do not operate: payments, email delivery, hosting status pages. Report those to the vendor.
  • Missing headers, cookie flags or email authentication records, without a working impact.
  • Self-XSS, clickjacking on a page with no sensitive action, and logout CSRF.
  • Anything that needs stolen credentials, or access you were not given.

What happens next

  1. 01

    We acknowledge a complete report within 5 business days.

  2. 02

    We aim to tell you whether it qualifies within 10 business days.

  3. 03

    We credit you by name only if you ask. Please wait 90 days before any public write-up.

Good faith

If you follow this policy, we will not take legal action over your research. This is not permission to attack systems we do not operate, or to keep testing once the impact is clear. Reports that break these rules are outside the program.

Report an issue

Tell us what is affected and what an attacker could do. Leave out other people’s personal data and passwords.

Known reports

Issues we have confirmed. We name who found them and, if there was a reward, the amount. We do not describe how they worked.

  • Sep 23, 2026 · High

    Exposed credentials in a legacy system

    Thanks to Mateo and Antonio.

    €1,000

  • Aug 30, 2026 · Low

    File type validation on image uploads

    Thanks to Adrian.

Security bounty program | TPP