E-goi Bug Bounty Program
At E-goi, our Development and Security team strives to always keep our platform safe from security breaches and annoying, sometimes compromising, bugs. In order to keep that commitment we run a Bug Bounty Program so that anyone can safely, and responsibly, disclose to us any unknown bugs or security flaws that might have been found.

How to Report
If you wish to contact us about a possible security flaw or bug we recommend that you either click the button below and fill in the form, or directly send us an email to our Security Team at security [at] e-goi [dot] com.
We ask that you please describe to us in your Email, with as much detail as possible, what the flaw is and, more importantly, the steps to reproduce it. We will try to review your report as soon as possible and reply back to you to inform you if we were able to confirm and reproduce the existence of the flaw, or to further inquire about it.
If you want to report more than one issue please send a separate Email for each one so that they can be processed individually.
We also ask that you do not publicly disclose your findings without our approval first.

Rewards
Our Bug Bounty Program rewards any reporter that submits an issue that is both new and unknown to us. The Rewards range, depending on the severity of the security flaw that was found, from $10 USD, $40 USD or $100 USD if they are classified accordingly as a Low, Medium or High severity flaw.
As a norm, but not always, we tend to qualify any security flaw that disclosures sensitive information, or might compromise the availability of our service, as an immediate High Risk reward, any Stored exploits are usually a Medium, while other reports like Reflected XSS or Open URL Redirection tend to be qualified as Low Risk.
In order to qualify for payment you must have a valid Paypal Address account, the Report must be reproduced by us, and it must be unique and not reported before. We will only reward the first reporter for the same issue. If you post a duplicate report we will Forward you the original report to confirm it.

Scope of the program
We are only looking for reports concerning our main platform E-goi, that you can access using the URL: https://login.egoiapp.com
We ask that you do not attempt to do any actions to existing accounts and instead create your own account to do your own tests, you can create an account for free 🙂 If you think you found a flaw that might compromise the availability of our platform we ask that you get in contact with us instead of testing it first.
While we welcome any report concerning flaws with third party software, like WordPress, Jira, LiveAgent, etc, that we might be using for our Website or Blog, these don’t usually qualify for a reward unless they represent a Data Breach.
The most common vulnerabilities that usually are rewarded are:
AI-Assisted Research and Reports
AI is welcome. Evidence is required! E-goi welcomes and encourages the use of AI-assisted tools, static analysis platforms, code review assistants, and other modern security research technologies as part of the vulnerability discovery process.
We recognize that these tools can help researchers identify potential security weaknesses more efficiently and can contribute positively to the security of our platform. We actively encourage the responsible use of AI-assisted analysis, static review tools, and other modern security research techniques.
However, due to the significant increase in AI-generated vulnerability reports across the industry, and in order to ensure that our security team can focus its efforts on validating and remediating genuine security issues, all submissions to the E-goi Bug Bounty Program must demonstrate a real, reproducible vulnerability.
Findings based solely on theoretical analysis, source code inspection, AI-generated hypotheses, inferred attack paths, or local simulations without practical validation in the E-goi production environment are generally not eligible for rewards and may be closed as Informational, Not Applicable, or Unable to Reproduce.
While AI can be an excellent tool for identifying potentially interesting code patterns, the existence of a potentially vulnerable pattern does not necessarily indicate an exploitable condition. Researchers are therefore expected to validate their findings and provide sufficient evidence, including a proof of concept (PoC), to demonstrate that the reported issue is reachable, reproducible, and has a realistic security impact.
To be considered valid, a report should include:
– Clear and reliable reproduction steps
– Evidence that the issue is currently reproducible in the production environment
– A proof of concept (PoC) demonstrating the reported behavior
– Sufficient technical detail for our team to independently reproduce and validate the finding
– A realistic security impact resulting from successful exploitation
The presence of code patterns that appear vulnerable does not necessarily indicate an exploitable condition. Modern applications frequently contain additional runtime controls, validation mechanisms, framework protections, environmental restrictions, or compensating controls that may prevent exploitation despite what static analysis suggests.
For this reason, E-goi evaluates findings based on demonstrated impact and reproducibility rather than theoretical possibility.
Reports that consist exclusively of AI-generated analysis, speculative attack scenarios, or unverified code observations without a working proof of concept may be closed as Informational, Not Applicable, or Unable to Reproduce.
Researchers who leverage AI effectively while providing practical validation, reproducible evidence, and high-quality technical analysis are welcome participants in our Bug Bounty Program and will receive the same consideration as any other researcher.
