We may collect the following categories of information.
Account and Identity Information — this may include name, email address, username, password credentials, company name, job title, country, profile photo, account role, researcher profile, skill level, verification status, certification status, and account preferences.
Company and Program Information — for customers, we may collect company details, billing information, authorised users, security contacts, program scope, target assets, domains, IP ranges, application details, cloud environment information, bounty rules, disclosure preferences, and remediation workflow information.
Researcher and Academy Information — for researchers and learners, we may collect skill assessments, CTF performance, certifications, submitted reports, reputation data, program invitations, assignment history, payout details, learning progress, and profile tags such as web, API, mobile, cloud, infrastructure, binary, or other security categories.
Vulnerability Reports and Security Content — we may collect vulnerability reports, proof-of-concepts, screenshots, logs, affected URLs, code snippets, reproduction steps, severity assessments, business impact descriptions, remediation notes, comments, attachments, and triage decisions. You should avoid submitting unnecessary personal data, secrets, credentials, customer data, production data, or sensitive information unless required and authorised for a valid security report.
Payment and Billing Information — we may collect billing name, billing address, tax information, invoice records, subscription details, payment status, payout records, and limited payment metadata. Full payment card or banking details may be processed by third-party payment providers.
Device, Usage, and Log Information — we may collect IP address, browser type, device type, operating system, pages viewed, actions taken, session data, API usage, login events, error logs, security logs, referral URLs, approximate location, timestamps, and diagnostic data.
Cookies and Similar Technologies — we may use cookies, pixels, SDKs, local storage, and similar technologies to operate the website, keep users signed in, remember preferences, secure accounts, measure usage, improve performance, and support marketing where allowed.
Communications — we may collect messages, emails, support tickets, chat messages, community posts, feedback, survey responses, sales communications, and call or meeting notes.
Integration Data — if you connect third-party tools, we may process information from integrations such as code repositories, issue trackers, cloud services, SIEM tools, communication platforms, identity providers, ticketing systems, or payment processors.