Help us protect our ecosystem. We reward security researchers for discovering and reporting vulnerabilities.
Vidio invites security researchers, hackers, and the general public to participate in our Bug Bounty program, aimed at discovering and addressing security vulnerabilities in our website and mobile applications. We value your commitment to enhancing the security of our services.
If you find any method of stealing our content, please inform us as we are interested in exploring it further. Good luck and enjoy the hunt!
If you suspect you've uncovered a security vulnerability, please report it right away. Submit your findings to security@vidio.com
Your report should include:
Rules of Engagement:
Before conducting security research on Vidio, please read and understand the following guidelines and regulations:
Our rewards are impact-based, meaning we offer higher rewards for vulnerabilities that could expose sensitive user data, while lower or no rewards for vulnerabilities that only allow minor actions, such as defacing a microsite. During our reward meetings, we consider the potential impact of a malicious attacker exploiting the vulnerability and compensate accordingly. We only reward the first reporter who provides actionable information to identify the issue.
Ultimately, reward payouts are at our discretion, but we strive for fairness. Some researchers may disagree with our decisions, but we aim to be ethically responsible and trust that the majority will find their rewards fair and, in many cases, generous. The program will evolve over time. Accepting a reward signifies agreement not to disclose the vulnerability to the public.
| In-Scope Domains | In-Scope Vulnerability Classes |
|---|---|
|
Content Protection:
|
Please keep in mind that your participation in the Bug Bounty Program is entirely voluntary and is subject to the terms and conditions outlined on this page ("Terms & Conditions"). You acknowledge that you have read and agree to these Program Terms by submitting a site or product vulnerability to Vidio.
Bounty is committed to maintaining the confidentiality of any material or information related to Vidio bugs that is acquired directly or indirectly through written, electronic, oral, or observational means ("Confidential Information"). Disclosure of any Confidential Information to third parties by Bounty is strictly prohibited, unless expressly authorized by Vidio. Bounty shall take all reasonable measures to protect the confidentiality of Confidential Information, including but not limited to restricting access to such information only to those third parties who have been informed of its confidential nature and have agreed not to disclose or use such information other than as authorized by Vidio. Any unauthorized or suspected use or disclosure of Confidential Information by Bounty must be promptly reported to Vidio. However, the foregoing provisions do not apply to information that Bounty was already aware of prior to Vidio's exposure, information that was publicly available through no fault of Bounty, information that was disclosed legally to Bounty by a third party without any obligation of confidentiality to Vidio, or information that was independently developed by Bounty without reference to Confidential Information.
We take our Bug Bounty Program seriously and are committed to providing a secure platform for our users. Therefore, Vidio reserves the right to modify or terminate the Bug Bounty Program, including its policies, at any time and without notice. As a result, Vidio may revise these Program Terms and policies at any time by publishing an updated version on our website. By participating in the Bug Bounty Program after such changes have been made, you agree to accept the Program Terms, as revised.
Dedicated to the ethical hackers who help secure our platform. We recognize researchers whose vulnerability reports have been validated by our team.
Each listed researcher will be displayed with the severity level of their accepted findings (Low, Medium, High, or Critical). Reports categorized as Informational are not eligible for Hall of Fame recognition.
We appreciate your contributions in helping us strengthen our platform’s security.
| Researcher Name | Valid Reports |
|---|---|
| Eric Head | 1 |
| Noobsid | 4 |
| Azhari Harahap | 3 |
| john john | 1 |
| Maulana Noer Fauzy | 2 |
| Milan | 1 |
| Nitish Shah | 1 |
| Vlad Starkov | 1 |
| Ardyan Vicky Ramadhan | 7 |
| Ivan Ezechial Suratno | 1 |
| Aviad Carmel - Salt Security | 1 |
| Awaken Sin | 1 |
| Bagas | 1 |
| Galatia Sijabat | 1 |
| Gaurav Wagh | 1 |
| Mori Tafata | 3 |
| Putra Aji Adhari | 4 |
| Rafi Andhika Galuh | 4 |
| Rama Aryo Prambudi | 1 |
| Rona Febriana | 1 |
| Stephan Stark | 1 |
| Stevanus Lieberto | 1 |
| Thomas W | 1 |
| Aditya Singh | 1 |
| AM45-51TUM074NG | 1 |
| Aidil Arief | 2 |
| Aman | 1 |
| Amir Farhan | 1 |
| amirfaki234@gmail.com | 1 |
| Andika Fransisco | 4 |
| Ashutosh Shukla | 2 |
| Bahtiyar Istiyarno | 1 |
| Bug Hunter | 1 |
| Faiz Hanafi | 1 |
| Fawwas Hamdi | 2 |
| Foysal Ahmed Fahim | 2 |
| Guarded Researcher | 1 |
| Hefiar Prasdianto | 2 |
| Helmay Cahyadi | 1 |
| IdZrack | - |
| Joshua Ingya | 1 |
| Koutrouss | 2 |
| Oliver | 1 |
| Ranjeet | 1 |
| RHYru9 Reyhansyah | 1 |
| SHIVAM KUMAR | 1 |
| shivanya | 1 |
| Soultan Muhammad Albar | 1 |
| Tushar Sharma | 1 |
Welcome to our updates log. We will post any significant changes to our scope, reward, or program status here.
We have completely revamped our Bug Bounty landing page for better readability, a modern aesthetic, and clearer scope guidelines. Happy hunting!