# Distributed Systems, Inc. — Paid Bug Bounty

Status: Active. Launch and effective date: October 6, 2026.
Public rules: https://distributed.systems/bug-bounty
Program owner and submissions: Arthur Colle, arthur@distributed.systems.

## Five graduated cash rewards

| Tier | Demonstrated impact | USD reward |
|---|---|---:|
| 1 — Low | Reproducible security weakness with limited exposure or narrow impact, beyond a purely cosmetic or best-practice observation | $20 |
| 2 — Moderate | Limited disclosure or permission bypass affecting a researcher-controlled account or restricted set of non-sensitive resources | $75 |
| 3 — High | Substantial access-control failure, account takeover or unauthorized action demonstrated in an approved test environment | $200 |
| 4 — Critical | Cross-tenant boundary failure, sensitive-secret exposure or arbitrary execution across a significant trust boundary in an approved environment | $500 |
| 5 — Exceptional critical | Reliable exploit or chain with broad agent-platform impact, such as privileged execution or systemic containment failure, demonstrated safely in an approved environment | $750 |

Awards are USD cash, not product credits. Severity considers demonstrated impact, exploitability, required privileges, affected data and reach. One award per distinct root cause goes to the first complete eligible report. A chain is assessed as one finding by its combined impact. An isolated reproduction suffices; never access other people's data or expand an exploit to prove larger impact.

## Scope and authorization

Local, isolated testing of company-owned source published and identified as DSCO, Chimera, Tool Management API or GraphSub is in scope, including authentication, authorization, routing, tool execution and agent containment. Use source linked by our official product pages or https://github.com/arthurcolle/dsco. Only code we own or maintain is included. Non-disruptive checks of the public distributed.systems marketing website are also included.

Active testing of production APIs, authentication, model gateways or execution services requires Arthur's written approval naming exact assets, test accounts, techniques and dates. Customer data, other tenants, production accounts and backend infrastructure are outside open authorization. Product listings, subdomains and shared hosting addresses do not independently provide testing permission. Third-party providers, cloud platforms, customer systems and personal accounts are excluded. Stickerfacet's former deployment is not an active target.

## Report submission

Email arthur@distributed.systems with DSCO bug bounty in the subject. Provide the product, revision or approved asset, authorization reference for live tests, reproducible steps with synthetic data and your own accounts, expected and observed behavior, demonstrated impact, minimal sanitized evidence, and contact information. Include a suggested fix when available.

Do not email credentials, customer records or full exploit dumps; request a secure transfer method if necessary. We aim to acknowledge within three business days and provide initial triage within ten business days.

## Eligibility and payment

Eligible reports identify previously unknown, reproducible, meaningful vulnerabilities in scope and follow these rules. Validated eligible reports receive the published reward for their assigned tier. Severity and duplicate decisions are explained and may be reviewed on additional evidence.

Informational observations, unvalidated scanner output, unsupported version warnings, cosmetic issues, social engineering, spam, denial of service, brute force and reports requiring prohibited access are not reward-eligible. Current employees and contractors are not eligible for findings arising from assigned work.

After validation, eligibility checks and agreement on a lawful payment method, rewards are paid in USD within 30 calendar days. Required payment and tax details are collected privately after acceptance. No fee, purchase or product-credit redemption is required.

Use minimum necessary proof. Stop on encountering another person's data; report accidental exposure without retaining it. Do not modify or delete data, persist access, disrupt service or publicly disclose findings before coordinated remediation. Recognition is optional; anonymity is welcome.

We authorize good-faith research within these scope and conditions and will not pursue legal action for that authorized work. This permission applies only to our assets and does not authorize third-party access.

## Changes and history

Program changes will be dated on the public page. Reports received while active are evaluated under the published terms then in force. This paid program launched October 6, 2026. Earlier May 2025 Stickerfacet reports are historical vulnerability handling, not twelve months of this paid program.
