Bug Bounty Program

NCSE Network takes the security of our systems and customer data seriously. If you find a security vulnerability in our systems, please report it responsibly as described below. For confirmed vulnerabilities, we offer a certificate of appreciation and NCSE Network Credit.

How to Report

Email security@ncse.tw with a subject starting with "[Bug Bounty]", and include as much of the following as possible:

  • The affected URL, host, or service
  • Vulnerability type and detailed reproduction steps
  • Potential impact
  • Proof of concept (screenshots, video, or requests)
  • Your contact details and the name to appear on the certificate

Rewards

For confirmed vulnerabilities, we provide:

  • A certificate of appreciation
  • NCSE Network Credit, usable for VPS purchases, Discord Nitro, or a HackTheBox subscription

Credit amounts depend on severity. We do not publish fixed amounts; each reward is discussed individually with the reporter. For duplicate reports, the first complete report is rewarded.

Scope

This program covers systems operated by NCSE Network, including:

  • The ncse.tw website
  • The client.ncse.tw client area
  • blog.ncse.tw and other *.ncse.tw services

Out of Scope

  • Denial of service (DoS / DDoS) or high-volume automated requests
  • Social engineering, phishing, or physical attacks
  • Customer-managed VPS instances and the services running on them
  • Vulnerabilities in third-party platforms or services
  • Automated scanner reports without demonstrated impact, missing security headers, and similar low-risk configuration issues

Rules of Engagement

  • Do not access, modify, or delete data that is not yours; stop as soon as the vulnerability is confirmed
  • Do not disrupt our services or other users
  • Do not disclose vulnerability details publicly before a fix is released
  • Comply with applicable laws of Taiwan (R.O.C.)

Process

  • We respond within 5 business days of receiving your report
  • We confirm and remediate the vulnerability within 2 months
  • Once fixed, we discuss and issue your certificate and Credit

Safe Harbor

NCSE Network will not pursue legal action against researchers who act in good faith and follow the rules above.