If you find a serious security issue such as any of the following issues, please contact us with relevant details including steps to reproduce or a proof-of-concept.
Authentication or session problems
Improper access to sensitive data
Broken access controls
Anything from the OWASP Top 10 Project
Upon discovering a vulnerability, we ask that you act in a way to protect our users' data:
Inform us as soon as possible.
Test against fake data and accounts, not our users' private data (please ask if you'd like a free account to work on this).
Work with us to close the vulnerability before disclosing it to others.
Sema does not have a bounty program.
We do not offer bug bounties for discovered vulnerabilities. We hope that if you discover vulnerabilities in the course of your work that you share them with us so we can improve the health of the internet ecosystem.