Bug Bounty Program
2026.10
Program launch date: October 1, 2025 Submissions: bounty@bioscope.ai
Bioscope AI builds clinical software that handles some of the most sensitive data there is, including patients’ whole genome sequences. We welcome help from security researchers in finding vulnerabilities before attackers do, and we pay cash rewards for valid reports that demonstrate real security impact.
Scope
Testing is permitted only against our development environment. It runs the same application code as production but is isolated from production systems.
In scope
| Asset | Description |
|---|---|
app.dev.bioscope.ai | Bioscope AI web application (physician and practice users) |
api.dev.bioscope.ai | Bioscope AI backend API |
ws.dev.bioscope.ai | Bioscope AI real-time (WebSocket) API |
app.dev.bioscopeconnect.com | Bioscope Connect web application (patient users) |
api.dev.bioscopeconnect.com | Bioscope Connect backend API |
auth.dev.bioscope.ai, auth.dev.bioscopeconnect.com | Login flows for the applications above (our configuration only, see below) |
Out of scope
- All production systems, including
app.us.bioscope.ai,bioscopeconnect.com,api.us.bioscope.ai, and any other host not listed above. Testing production is not authorized under this program and is not covered by safe harbor. - Any domain or IP address not listed in the in-scope table, including other
*.dev.bioscope.aihosts. - Our marketing website (
www.bioscope.ai) and this documentation site. - Third-party services and vendors, including our identity provider’s platform, AWS, payment processors, laboratory partners, and EHR vendors. Misconfigurations of our tenant on a third-party service are in scope when reached through an in-scope asset; vulnerabilities in the vendor’s own platform should be reported to that vendor.
- Email infrastructure, including
mail.dev.bioscope.ai. - Bioscope employees, offices, and physical security.
Rewards
We pay for valid, original reports with demonstrated security impact. Reward amounts are based on severity, which we assess using CVSS v4.0 adjusted for the real-world impact on Bioscope AI, our customers, and their patients.
| Severity | Reward (USD) |
|---|---|
| Critical | $1,000 – $2,000 |
| High | $500 – $1,000 |
| Medium | $150 – $500 |
| Low | $50 – $150 |
We give the most weight to issues that could expose or modify patient or practice data, especially genomic or other health data, or that let a user cross account, practice, or patient boundaries.
To be eligible for a reward:
- The vulnerability must be in an in-scope asset and must be reproducible.
- You must be the first to report it. Duplicates are rewarded only for the first valid report.
- The report must demonstrate security impact. Theoretical issues without a realistic attack scenario are not eligible.
- You must follow the rules in this policy.
- You must not be a current or former (within the last 12 months) Bioscope employee or contractor, or an immediate family member of one.
- You must not be on a U.S. sanctions list or located in a country subject to U.S. sanctions, and we must be legally able to pay you.
Reward amounts and eligibility are determined by Bioscope AI at its discretion. Multiple reports with the same root cause may be treated as one report. You are responsible for any taxes on rewards you receive, and we may ask for tax information before paying.
Not eligible
- Findings from automated scanners without a demonstrated, exploitable impact
- Missing security headers, cookie flags, or best-practice configurations without a demonstrated exploit
- Clickjacking on pages without sensitive actions
- CSRF on logout or other actions with no security impact
- Self-XSS, or issues that require an unlikely user interaction
- Rate limiting or brute-force issues on non-authentication endpoints
- Username or email enumeration without further impact
- Reports about outdated software versions without a working proof of concept
- Denial-of-service, resource exhaustion, or volumetric issues
- SPF, DKIM, DMARC, or other email configuration issues
- Social engineering or phishing of Bioscope staff, customers, or patients
- Vulnerabilities only exploitable on unsupported or outdated browsers
- Issues in third-party services that are not caused by our configuration
Rules of engagement
- Only test in-scope assets. If you believe an issue also affects production, describe it in your report. Do not test it against production.
- Use only test accounts. Use accounts you create or that we provide, and only interact with data you created. To request test accounts, email bounty@bioscope.ai.
- Stop at proof of concept. Do not access, modify, or delete data beyond what is needed to demonstrate the issue. Do not keep data, pivot further into our systems, or establish persistence.
- Stop if you find real data. The development environment is not intended to hold real patient or customer information. If you encounter data that appears to be real personal or health information, stop testing immediately, do not copy or keep it, and report it to us right away.
- Do not degrade service. No denial-of-service testing, and keep automated scanning to a reasonable rate (no more than 10 requests per second).
- No social engineering or physical testing.
- Keep it confidential. Do not disclose the vulnerability publicly or to anyone else until we have fixed it and given written permission.
How to submit a report
Email your report to bounty@bioscope.ai. Please include:
- The affected asset (URL or API endpoint)
- The type of vulnerability and its security impact
- Step-by-step instructions to reproduce it
- A proof of concept, such as requests and responses, screenshots, or a short video
- The test account(s) you used
- How you would like to be credited, if at all
Please submit one vulnerability per report unless several issues must be chained together to have impact.
What to expect from us
| Stage | Target |
|---|---|
| Acknowledge your report | Within 3 business days |
| Initial triage and severity assessment | Within 10 business days |
| Reward decision | Within 30 days of triage, or after the fix for complex issues |
We will keep you updated while we work on a fix and will let you know when the issue is resolved. With your permission, we are happy to credit you publicly.
Safe harbor
When you make a good-faith effort to follow this policy while researching in-scope assets, we consider your research to be authorized. Specifically:
- We will not pursue or support legal action against you for accidental, good-faith violations of this policy.
- We consider your research authorized under the Computer Fraud and Abuse Act and similar laws, and we will not bring a claim against you for circumventing technical measures that are in scope.
- We waive any restrictions in our terms of service that would otherwise prohibit research conducted under this policy.
If a third party brings legal action against you for activity conducted under this policy, we will make it known that your actions were authorized by us.
Safe harbor applies only to in-scope assets. It does not cover production systems, third-party services, or any activity that violates the rules above. If you are unsure whether something is in scope or allowed, ask us at bounty@bioscope.ai before testing.
Changes to this program
We may change or end this program at any time. Changes take effect when they are published on this page. Reports submitted before a change are handled under the terms in effect when they were submitted.