Bug Bounty Program

Last update: August 18, 2026

CleanShot team looks forward to working with independent security researchers. As long as you comply with this policy, you are welcome to test and report any vulnerabilities you find in our services. We offer rewards for valid reports to encourage ethical hackers to help us keep our users safe.

Program Rules

Here are the base rules of the CleanShot Bug Bounty program:

  1. Each report must demonstrate a real security vulnerability affecting the confidentiality, integrity, or availability of the service.
  2. Each report must include the steps necessary to reproduce the issue (Proof of Concept).
  3. Provide us with enough time to resolve the issue before making any information public.
  4. Multiple vulnerabilities caused by the same underlying issue will be awarded one bounty.
  5. In case multiple researchers report the same vulnerability, only the first report will be rewarded.
  6. Respect user privacy. Do not access user data beyond what is necessary to demonstrate the vulnerability. Do not post comments under other users' content. Do not modify or delete data that does not belong to you.
  7. Low-quality reports will not be rewarded, may be ignored, and may result in exclusion from the program. This includes raw output from automated or AI tooling that has not been reproduced against the live service, templated reports containing details of another issue, and reports that greatly exaggerate the severity of the issue.

Rewards

All bounty amounts are determined by the CleanShot team and are based on the severity of the vulnerability, its impact, and the quality of the report. The amounts below are a general guideline for reward amounts:

CriticalHighMediumLowInfo
$4000$1000 – $2000$500 – $1000$100 – $500$50 – $150

Scope

The following components are in scope:

  1. CleanShot X macOS app:
    • The latest version of CleanShot X desktop app downloaded from cleanshot.com or installed through Setapp.
  2. CleanShot Cloud and CleanShot license management web apps, backend and infrastructure:
    • cleanshot.com/*
    • *.cleanshot.cloud/*
    • share.cleanshot.com/*
    • cln.sh/*
    • updates.getcleanshot.com/*
    • Any custom domain you connect in Advanced settings on a Pro account.
    • licenses.cleanshot.com/*
    • legit.maketheweb.io/*
    • S3 buckets, CloudFront distributions, and other asset URLs referenced by the domains above, where the context indicates that we own and operate them.

If you are unsure whether something belongs to us, ask at security@cleanshot.com.

Out of scope

The following resources are explicitly out of scope for the program:

  • docs.cleanshot.com
  • status.cleanshot.com
  • Custom domains of other customers that you did not connect yourself.

The following actions and finding types are considered out of scope for the program, and any report that uses these techniques or has these characteristics will not be rewarded:

  1. Missing best practices (e.g. email SPF/DKIM/DMARC, Content Security Policy, HTTP headers, SSL configuration, DNSSEC, DNS records) without a working Proof of Concept demonstrating a real vulnerability.
  2. Vulnerabilities requiring unlikely user interaction.
  3. Well-known vulnerable software or libraries without a relevant Proof of Concept.
  4. UI and UX bugs, spelling mistakes, and errors in application logic that do not have a security impact.
  5. Password policy issues.
  6. Session management behavior that is by design, including tokens remaining valid after enabling or disabling two-factor authentication.
  7. Rate limiting issues.
  8. Simple DoS attacks. A DoS attack is only in scope if a vulnerability allows an attacker to consume significant resources with a small number of requests.
  9. Intended behavior of the application.
  10. User enumeration.
  11. Unsafe token storage without demonstrating a practical attack.

Prohibited Actions

  1. Social engineering or phishing of CleanShot employees or contractors.
  2. Physical attacks against CleanShot personnel or infrastructure.
  3. Brute forcing directories or subdomains with automated tools like DirBuster.
  4. Any testing that affects real users, including posting comments under their content.

Safe Harbor

Any activities conducted in a manner consistent with this policy will be considered authorized conduct, and we will not initiate legal action against you.

Reporting Process

If you believe you have found a security vulnerability in any CleanShot product, or have any questions or suggestions about this policy, please contact us at security@cleanshot.com.

While we do our best to respond to every report, we reserve the right to ignore reports and exclude researchers from the program if they do not follow the rules outlined in this policy, especially if reports appear to be spam, low-quality, or out of scope.

Thank you for helping us keep CleanShot safe!