TraceX - Private Skill-based Bug Bounty & Managed Disclosure PlatformLearn More
Legal

Terms of Use

By accessing or using BugsTrace, you agree to these Terms. If you do not agree, do not use our services.

Last updated: June 4, 2026
01

What BugsTrace Provides

BugsTrace is an AI-native cybersecurity company providing products and services that may include the following. Some services may be provided as self-service software. Others may be provided as managed services, beta products, private programs, enterprise deployments, or custom engagements.

  • BugsTrace Platform: private skill-matched bug bounty and managed disclosure.
  • BugsTrace Academy: CTF training, researcher assessment, and certification.
  • BugsTrace Trigger: AI-assisted vulnerability report triage.
  • BugsTrace Agent: autonomous and assisted security testing.
  • BugsTrace Copilot: AI security assistant for developer workflows.
  • BugsTrace Intel: vulnerability intelligence and risk insights.
  • BugsTrace Radar: attack surface discovery, monitoring, and prioritisation.
  • Related APIs, dashboards, reports, integrations, support services, and managed security workflows.
02

Eligibility

You must be at least 18 years old, or the age of legal majority in your jurisdiction, to use BugsTrace as a company user, researcher, customer administrator, or paid subscriber.

By using BugsTrace on behalf of a company, organisation, university, government body, or other entity, you confirm that you have authority to bind that entity to these Terms.

03

Accounts and Security

You are responsible for keeping your account credentials secure. You must not share your login credentials, allow unauthorised access to your account, or use another person's account without permission.

You agree to provide accurate account information and keep it updated. BugsTrace may suspend or terminate accounts that provide false information, impersonate another person, violate these Terms, or create security, legal, or operational risk.

You must notify BugsTrace immediately if you believe your account, API key, dashboard, integration, or credentials have been compromised.

04

Authorised Security Testing Only

BugsTrace is a cybersecurity platform. However, using BugsTrace does not give you permission to test, scan, attack, access, exploit, disrupt, or assess any system unless you have clear written authorisation.

Researchers may only test targets that are assigned to them or clearly listed as in-scope within a BugsTrace program. Customers may only submit assets, domains, applications, repositories, APIs, cloud environments, or systems that they own or are legally authorised to test.

You must not use BugsTrace to conduct unauthorised hacking, credential attacks, malware activity, phishing, denial-of-service attacks, social engineering, extortion, data theft, privacy invasion, or any activity that violates law or third-party rights.

05

Researcher Rules

If you participate as a researcher, you agree to follow the rules of each program, including scope, testing limits, reporting format, disclosure rules, time limits, rate limits, and communication requirements. Unless expressly allowed by the program, you must not:

  • Access, copy, alter, delete, or exfiltrate data beyond what is necessary to prove a vulnerability.
  • Perform destructive testing.
  • Interrupt service availability.
  • Use phishing or social engineering.
  • Access employee, customer, patient, financial, or private user data.
  • Publicly disclose findings before written permission is granted.
  • Submit false, duplicate, exaggerated, AI-generated, scanner-only, or low-quality reports.
  • Attempt to bypass BugsTrace triage, payout, identity, or assignment systems.

BugsTrace may reject reports, reduce payouts, suspend researchers, or remove researchers from programs where conduct is unsafe, misleading, abusive, unlawful, or outside scope.

06

Customer Responsibilities

Customers are responsible for ensuring that all submitted assets, scopes, integrations, repositories, domains, environments, cloud accounts, APIs, and systems are authorised for security testing.

Customers must provide clear scope, testing rules, bounty rules, access instructions, exclusions, and any legal or operational restrictions. Customers are responsible for reviewing reports, remediating vulnerabilities, paying accepted bounties where applicable, and complying with their own legal obligations.

BugsTrace may assist with triage, communication, prioritisation, reporting, and managed disclosure, but BugsTrace is not responsible for a customer's failure to fix vulnerabilities, maintain secure systems, or respond to security risks.

07

AI Features and Automated Analysis

BugsTrace may use AI, machine learning, automation, scoring systems, or agentic workflows to assist with report triage, duplicate detection, severity scoring, bounty recommendations, vulnerability intelligence, attack surface analysis, code review, and security testing.

AI outputs are provided to assist human decision-making. They may be incomplete, inaccurate, outdated, or unsuitable for a particular environment. You are responsible for reviewing AI-generated outputs before relying on them.

BugsTrace does not guarantee that AI systems will find every vulnerability, correctly score every report, prevent every attack, or produce error-free recommendations.

08

Reports, Submissions, and Content

You may submit reports, comments, messages, code snippets, logs, screenshots, proof-of-concepts, documents, files, target information, vulnerability details, or other content through BugsTrace.

You retain ownership of content you submit, but you grant BugsTrace a worldwide, non-exclusive, royalty-free licence to host, process, analyse, reproduce, display, transmit, transform, and use that content as needed to provide, secure, improve, and operate the services.

For vulnerability reports, you also grant BugsTrace the right to share the report with the relevant customer, authorised program owner, triage team, payment processor, legal reviewer, or service provider as needed to operate the program.

You must not submit content that is unlawful, infringing, malicious, deceptive, abusive, defamatory, privacy-invasive, or outside the authorised purpose of the service.

09

Confidentiality and Responsible Disclosure

Program scopes, private targets, vulnerability reports, customer assets, internal dashboards, non-public product information, researcher assignments, bounty decisions, and security findings may be confidential.

You must not disclose confidential information except as authorised in writing by BugsTrace or the relevant program owner.

Researchers must follow responsible disclosure rules. Customers must not misuse researcher identity, reports, or proof-of-concepts. BugsTrace may coordinate disclosure timelines depending on program rules, legal obligations, and severity of risk.

10

Payments, Subscriptions, Bounties, and Fees

BugsTrace may charge subscription fees, platform fees, usage-based fees, managed service fees, enterprise fees, bounty transaction fees, or other charges. Unless stated otherwise, fees are in U.S. Dollars (USD).

Paid plans may renew automatically unless cancelled according to the applicable plan terms. Taxes, payment processing fees, currency conversion charges, and banking charges may apply.

Bounty payouts are subject to program rules, scope, report validity, severity, duplicate status, customer acceptance, payment availability, fraud checks, tax requirements, sanctions screening, and BugsTrace review.

BugsTrace may delay, reject, reverse, or withhold payouts where reports are invalid, duplicated, fraudulent, unlawful, outside scope, generated abusively, or connected to Terms violations.

11

No Guaranteed Results

Cybersecurity is complex and constantly changing. BugsTrace does not guarantee that its services will identify every vulnerability, prevent every breach, remove every risk, produce a particular security outcome, or satisfy every compliance requirement.

Reports, scores, dashboards, findings, recommendations, certifications, and intelligence are provided for security decision support. Customers remain responsible for their own security, engineering, legal, compliance, and remediation decisions.

12

Acceptable Use

You must not use BugsTrace to:

  • Violate any law, regulation, sanction, export control, or third-party right.
  • Conduct unauthorised security testing or attacks.
  • Upload malware, credential dumps, stolen data, illegal content, or harmful payloads except where expressly authorised for a controlled security report.
  • Interfere with BugsTrace systems, customers, researchers, or service providers.
  • Abuse APIs, scrape data, bypass rate limits, or reverse engineer protected systems.
  • Misrepresent identity, affiliation, skill, findings, or authorisation.
  • Use BugsTrace to build competing datasets, models, or services without written permission.
  • Harass, threaten, spam, or abuse other users.
  • Submit AI-generated reports at scale without meaningful validation.
  • Attempt to manipulate reputation, bounty, certification, triage, or ranking systems.
13

Intellectual Property

BugsTrace owns its platform, software, AI systems, designs, workflows, dashboards, documentation, trademarks, logos, product names, reports generated by BugsTrace, and related intellectual property.

You may not copy, modify, distribute, resell, sublicense, reverse engineer, or create derivative works from BugsTrace services except as expressly allowed in writing.

"BugsTrace," "BugsTrace Platform," "BugsTrace Academy," "BugsTrace Trigger," "BugsTrace Agent," "BugsTrace Copilot," "BugsTrace Intel," and "BugsTrace Radar" are brand assets of BugsTrace, Inc. You may not use them in a way that suggests endorsement, partnership, or affiliation without written permission.

14

Third-Party Services

BugsTrace may integrate with third-party services such as cloud providers, payment processors, identity verification tools, analytics tools, ticketing systems, communication platforms, code repositories, and security tools.

Third-party services are governed by their own terms and privacy policies. BugsTrace is not responsible for third-party services, outages, data practices, or security failures.

15

Beta and Experimental Features

Some BugsTrace features may be labelled beta, preview, experimental, early access, or pilot. These features may be incomplete, changed, limited, suspended, or discontinued at any time.

Beta features are provided "as is" and may not be suitable for production, compliance, or high-risk use without additional review.

16

Suspension and Termination

BugsTrace may suspend or terminate access if we believe you violated these Terms, created risk for BugsTrace or others, failed to pay fees, submitted false information, abused the platform, or used the services unlawfully.

You may stop using BugsTrace at any time. Termination does not remove obligations that should reasonably survive, including confidentiality, payment obligations, intellectual property restrictions, disclaimers, limitations of liability, and dispute terms.

17

Disclaimers

To the maximum extent allowed by law, BugsTrace services are provided "as is" and "as available." BugsTrace disclaims all warranties, express or implied, including warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, availability, and security.

BugsTrace does not warrant that the services will be uninterrupted, error-free, vulnerability-free, or free from harmful components.

18

Limitation of Liability

To the maximum extent allowed by law, BugsTrace will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, including lost profits, lost revenue, lost data, business interruption, loss of goodwill, security incidents, or remediation costs.

To the maximum extent allowed by law, BugsTrace's total liability for any claim will not exceed the amount paid by you to BugsTrace for the services giving rise to the claim during the three months before the event giving rise to liability, or USD $100 if you did not pay BugsTrace.

19

Indemnification

You agree to defend, indemnify, and hold harmless BugsTrace, Inc., its officers, directors, employees, contractors, affiliates, and service providers from claims, damages, liabilities, losses, costs, and expenses arising from your use of the services, your content, your security testing activity, your violation of these Terms, your violation of law, or your infringement of third-party rights.

20

Changes to These Terms

BugsTrace may update these Terms from time to time. We will update the effective date when changes are made. Material changes may be notified through the website, dashboard, email, or other reasonable method.

Continued use of BugsTrace after changes become effective means you accept the updated Terms.

21

Governing Law and Venue

These Terms are governed by the laws of the State of Delaware, United States, without regard to conflict-of-law rules.

Unless otherwise required by law, disputes will be resolved in the state or federal courts located in Delaware, and you consent to the jurisdiction of those courts.

22

Contact

For legal questions, contact: BugsTrace, Inc. Email: legal@bugstrace.com