1.1 The security of our users is a top priority at Astrill. We appreciate the work of security researchers and welcome responsible reports of vulnerabilities in our services. This page explains how to submit a report, what is in scope, the rules you must follow, and how rewards are decided.
1.2 This bug bounty program is a discretionary, voluntary initiative of Astrill. It is not a contest, an offer or a contract. Astrill may modify, suspend or terminate the program at any time without prior notice; the version published on this page at the time of your report governs. All determinations — including whether a report is valid, its severity, eligibility for a reward and the amount of any reward — are made by Astrill at its sole discretion and are final.
2.1 Send your report by email to bugbounty@astrill.com. This is our dedicated address for security reports; please do not submit vulnerabilities through customer support or any public channel.
2.2 A good report contains: a clear description of the issue; the affected URL or service (including version); step-by-step instructions to reproduce it; a minimal proof of concept; and your assessment of the security impact. Report exactly one vulnerability per email — see section 2.7.
2.3 Report a vulnerability promptly after you discover it. Do not stockpile issues.
2.4 We aim to acknowledge new reports within five business days and, where possible, will keep you informed about the progress of remediation.
2.5 Reports that withhold technical details pending a promise of payment (“pay first, details later”) are not accepted.
2.6 Send your report as plain-text email, with the full description, reproduction steps and evidence written in the body of the message. We do not open attachments, and we do not follow links to file-sharing services, external report platforms, video hosts or private repositories in order to read a report. Emails that carry attachments, or that require us to open a link or create an account before the details can be read, are ignored without reply. If an image would ordinarily be needed, describe its content in text; we will ask you for it separately if it turns out to matter.
2.7 One issue, one email. If you have found several vulnerabilities, send a separate email for each of them, each with its own subject line; never list several findings in a single message. We do not split bundled emails on your behalf: an email that describes more than one issue is treated as a single report of the first issue in it, and the remaining findings are not registered, are not assessed and earn no reward — resubmit them individually. The only thing that belongs together in one email is a chain of steps that is needed to demonstrate a single vulnerability; that is one issue. Keep any follow-up correspondence about a report in the same email thread.
3.1 In scope are the astrill.com website and member zone, together with the server-side API and VPN infrastructure that we operate and that they depend on.
3.2 The Astrill VPN applications themselves are not in scope. That means the Windows, macOS, Linux, Android and iOS clients, the router firmware and applet, and any other client software we publish. Findings in those applications are outside this program regardless of severity — see section 4.1(t). A weakness in the server-side API that an application talks to remains in scope, because that is our infrastructure rather than the client.
3.3 Everything not operated by Astrill is out of scope. This includes, for example, websites of resellers and affiliates, payment processors, app stores and other third-party services that merely integrate with Astrill. Please report issues in those systems to their respective operators.
4.1 The following categories are not accepted under this program and do not qualify for a reward:
(a) vulnerabilities in third-party software or services (see section 5);
(b) publicly known vulnerabilities (e.g. CVEs) identified only from version information, banners or fingerprinting, without a demonstrated compromise of our systems;
(c) denial of service, resource exhaustion, brute-force and rate-limiting findings, and any report whose demonstration requires degrading our services;
(d) social engineering or phishing of Astrill staff or customers, physical attacks against our facilities or infrastructure, and attacks against personal accounts or devices of Astrill staff. We also do not accept a report whose only asserted impact is that a finding could assist phishing, impersonation or social engineering: that argument can be made about any published name, byline or staff page, and on its own it is not a demonstrated security impact;
(e) email configuration findings (SPF, DKIM, DMARC and similar) without a practical, working exploit;
(f) missing security headers, cookie flags, clickjacking and similar best-practice observations without a demonstrated, practical security impact;
(g) SSL/TLS configuration observations (supported protocol versions, cipher suites, certificate details) without a practical attack;
(h) self-XSS, and issues that require a victim device that is already compromised, rooted or jailbroken, or that has an attacker-installed root certificate;
(i) open redirects, content spoofing, text injection and tabnabbing without a demonstrated security impact;
(j) username or email address enumeration, including enumeration of author, staff or contributor accounts and of the profile information those accounts publish;
(k) unverified output of automated scanners;
(l) issues reproducible only in outdated browsers, operating systems or client versions;
(m) side-channel findings — including timing, cache-timing and traffic-analysis claims — submitted without measurements. A report in this category must include the underlying data: the measured figures, the number of samples, the tooling or script used to collect them, and a working proof of concept showing that the difference is both statistically significant and practically exploitable. Describing the methodology by which such a difference could be measured, or asserting an outcome that was not actually measured, does not qualify;
(n) the absence of a hardening or defence-in-depth measure, reported on its own and without a demonstrated practical impact — for example a missing CAPTCHA, DNSSEC, CAA or Subresource Integrity, verbose error messages, disclosure of software versions, or a directory listing that exposes no sensitive content;
(o) cross-site request forgery on actions that carry no security impact, such as logging in or logging out;
(p) issues that require an attacker-in-the-middle position, or physical or local access to the victim's device or network;
(q) findings that rest on credentials or data leaked elsewhere, or on information that is already public — including material we publish deliberately, such as bylines, author pages, staff names and the profile links those pages carry — rather than on a weakness in our systems;
(r) behaviour that is inherent to the operation of a VPN service — for example shared exit IP addresses, our address ranges appearing in third-party blocklists, or the ability to reach arbitrary destinations through the VPN; and
(s) reports that do not contain enough detail to reproduce the issue, or where the reporter declines to supply that detail when asked; and
(t) vulnerabilities in the Astrill VPN applications themselves — the Windows, macOS, Linux, Android and iOS clients, the router firmware and applet, and any other client software we publish. This program covers our website, member zone and the server-side infrastructure behind them, and does not extend to the applications.
5.1 Vulnerabilities in software or services that Astrill does not develop or operate are not part of this program, even if Astrill uses the affected product. Please report them to the respective vendor or project.
5.2 That said, if you discover that Astrill runs a version of a third-party product that is affected by a known vulnerability, we welcome a note about it at bugbounty@astrill.com and will act on it. Such reports are appreciated, but pointing to a public advisory does not by itself qualify for a reward. Where a report demonstrates a concrete, previously unknown exposure of our systems, we may grant a reward at our sole discretion.
6.1 When researching, you must:
(a) test only with accounts and devices that you own or are explicitly authorized to use;
(b) never access, modify or delete data belonging to other users — if you encounter someone else's data, stop immediately and mention it in your report;
(c) limit yourself to the minimal proof of concept required to demonstrate the vulnerability, without pivoting further into our systems and without exfiltrating data;
(d) avoid any action that degrades our services, including high-volume automated scanning; and
(e) keep all information about the vulnerability and about our systems confidential in accordance with section 8.
6.2 Safe harbor: if you conduct your research in good faith and in compliance with this policy, Astrill will not initiate legal action against you or refer your research to law enforcement. This assurance does not extend to conduct that violates this policy or applicable law.
6.3 Astrill does not provide accounts, credentials, subscriptions, trial extensions or any other form of free or discounted access for testing purposes, and does not make exceptions on request. Your research must be carried out using access you already hold, within the limits of 6.1. Reports are assessed on their content; holding a paid account is neither required for a report to be accepted nor a factor in how it is rated.
7.1 Rewards are granted exclusively at Astrill's sole discretion. This includes whether a reward is granted at all, its amount and its form. We do not publish a reward table; each report is assessed case by case, based primarily on the demonstrated security impact and the quality of the report.
7.2 A reward can only be considered if all of the following are met:
(a) you are the first to report the issue — duplicate reports and issues already known to Astrill (including from internal testing) are not eligible;
(b) the issue is in scope and your research and report comply with this policy; and
(c) Astrill implements a fix or other change to its systems as a result of your report. If Astrill decides, after investigation, not to change anything — for example because the reported behavior is intended, the risk is accepted, or the issue is out of scope — no reward will be paid and no claim to a reward arises.
7.3 Rewards are paid exclusively in Bitcoin (BTC); no other payout method is offered. To receive a reward you must provide a valid Bitcoin address of a wallet that you own and control directly — that is, a self-custodial wallet whose private keys are held by you personally. Deposit addresses of cryptocurrency exchanges, brokers or other custodial platforms, and addresses belonging to any third party, are not accepted: such platforms commonly hold or freeze deposits from unknown senders pending sender information, and receiving payments from a third party may violate their terms of service. By providing an address you confirm it meets these requirements. Payment is made once, to the address you provide; Astrill is not responsible for funds that are delayed, held or lost because the address was not a wallet under your direct control, and such a payment will not be reissued. If you are unable or unwilling to accept payment in Bitcoin under these conditions, we will not be able to pay a reward.
7.4 Astrill employees and contractors, their immediate family members, and persons to whom Astrill may not lawfully make payments (for example due to applicable sanctions) are not eligible for rewards.
7.5 You are solely responsible for any taxes or duties arising from a reward in your jurisdiction.
7.6 Nothing on this page constitutes an offer or creates any obligation of Astrill to pay a reward. Participation in the program does not create any employment, agency or other contractual relationship between you and Astrill.
7.7 Before a reward is paid you must confirm to us in writing that you accept the confidentiality obligations in section 8 and that the reward is repayable if you breach them. That confirmation, together with this policy, sets the terms on which the reward is paid. If a reward has been paid and you then disclose a reported vulnerability in breach of section 8, Astrill may require repayment of the full amount. This does not affect section 7.6: nothing obliges Astrill to offer or to pay a reward in the first place.
7.8 The amount of a reward is communicated to you once and is not open to negotiation. Astrill does not entertain counter-offers or requests to increase an amount that has already been communicated. If you believe the severity assigned to your report is wrong, you may appeal once, within 7 days of being notified, and only by supplying new technical evidence that materially changes the demonstrated impact. An appeal is not an opportunity to restate the original report, and rewards paid by other programs for issues you consider comparable have no bearing on Astrill's assessment. Where an amount has been communicated and you continue to press for a different one, Astrill may close the report and withdraw the offer.
8.1 You must not disclose a reported vulnerability, in whole or in part, to any third party or to the public — including blog posts, social media, conference talks and vulnerability databases — without Astrill's prior written consent. This obligation is not time-limited: it continues to apply after the issue has been remediated, and remediation does not release you from it.
8.2 Astrill alone decides if, when and in what level of detail information about a reported vulnerability is published. We do not ordinarily publish vulnerability details, and no advisory, credit or other public acknowledgement should be expected.
8.3 Any violation of this section forfeits eligibility for a reward, voids the safe harbor in section 6.2 and, where a reward has already been paid, entitles Astrill to require its repayment under section 7.7.
Last Updated: August 2026