Bug bounty & responsible disclosure

Help us keep Utyls secure.

If you find a real security issue, report it to us in good faith. We take security reports seriously and aim to respond quickly and respectfully.

Report privately

Email support@utyls.com with clear reproduction steps.

Act in good faith

Test only what you need to prove the issue. Do not access, copy, or share other users’ data.

Rewards are discretionary

We may offer a reward for high-quality, high-impact reports, but submitting a report does not guarantee payment.

What to send

Include the affected URL or flow, steps to reproduce, expected impact, and anything else needed to verify the issue without guesswork.

What not to do

Do not degrade service availability, access mailboxes you do not control, or use bulk automated testing against production without permission.

Safe harbor

If you follow these rules, act in good faith, and give us a fair chance to fix the issue, we will treat your report as authorized research.

In scope

  • utyls.com properties and official Utyls subdomains
  • Authentication, dashboard, inbox processing, and billing flows
  • Security issues that could expose data, accounts, or service integrity

Out of scope

  • Social engineering, phishing, or physical attacks
  • Spam, denial-of-service, or automated account creation
  • Issues that require access to someone else’s mailbox content
  • Reports based only on missing headers, outdated libraries, or best-practice checklists without real impact