If you find a vulnerability in NeonProxies, we want to hear about it. This page sets out what is in scope, what we pay for, what we do not pay for, and how to report so there are no surprises on either side.
neonproxies.comRewards are for demonstrated impact on our systems or our customers. Amounts are in USD.
Acknowledged and fixed where warranted, but not paid. The full list is below so you can check before you write the report.
These are accepted as Low or Informational at most. We will read them and fix what is worth fixing, but no bounty is issued and a Critical or High label on the report does not change that.
Email support@neonproxies.com with the subject Security report. Include the affected URL, exact steps to reproduce, the account you used, and a proof of concept. We acknowledge within 5 business days and give a severity decision within 10 business days.
Machine-readable contact details are at /.well-known/security.txt.
Send a reportPolicy last updated 2026-09-02.