Responsible disclosure & bug bounty policy
Please tell us about any vulnerability you find in 4G Proxies USA. On this page: what is in scope, what we pay for, what we do not, and how to report, so no one is surprised.
Scope
In scope
- This website,
4gproxiesusa.com - The customer dashboard you use after signing in, plus the API
- Dashboard handling of rotation links, API keys and proxy credentials
Out of scope
- Proxy gateways, modem hosts and the mobile carrier networks that feed them
- Third-party services, for example payment processors, Telegram, Cloudflare or email providers
- Marketing assets served from legacy CDN paths
- Other people's customer accounts or data
What we pay
Rewards cover demonstrated impact on our systems or our customers. Amounts are in USD.
- Remote code execution on our servers
- SQL injection reading customer data or writing it
- Any account opened without its credentials through an authentication bypass
- Payment or balance manipulation to get proxies, credit or refunds for nothing
- Bulk exposure of personal data or proxy credentials of other customers
- Reading or changing proxies, orders or account details that belong to another customer, through IDOR
- Stored XSS running in the session of another customer or an admin
- Getting admin functions from a customer account by privilege escalation
- Server-side request forgery reaching internal services
- Taking another account's API key, rotation link or session
- CSRF where the action changes the account's state
- Reflected XSS where a victim must click a link first
- A rate-limit bypass that ends with a demonstrated account takeover
- Mistakes in pricing or business logic that demonstrate a financial impact
We acknowledge and fix these if warranted, but pay nothing. We put the full list below so you can check it before you report.
What we do not pay for
The highest we accept these at is Low or Informational. We read them and fix the ones worth fixing, but we pay no bounty, even when the report says Critical or High.
- Session still valid after logout or a password reset or change, until the token expires
- CSP, HSTS, X-Frame-Options or Referrer-Policy headers that are missing or “weak”, with no exploit that works
- Clickjacking on any page that has no sensitive action
- Cookie attributes for cookies that aren't used for sessions
- Listing out emails or usernames, including through response timing or error messages
- Remarks on the login, forgot-password or rate-limit behavior without a proven account takeover
- Personal views on password policy, like length, complexity, common-password lists and no forced rotation
- Not having two-factor authentication, or having 2FA as optional
- Self-XSS or XSS triggered only by the attacker inside their own session
- CSRF on the login, logout, language or another non-sensitive form
- Open redirects that give away no token or credential
- Software version, server banner, stack trace or path info that holds no sensitive data
- SPF, DKIM or DMARC configuration reports
- Output of automated scanning tools with no proof of concept
- Denial-of-service or resource-exhaustion tests, brute force, or any test that makes load
- Tricking our staff or customers through social engineering or phishing; physical attacks
- Issues with the third parties we use, for instance payment processors, Telegram, Cloudflare or email providers
- Older library versions without an exploit that works against our deployment
- Attacks where you first need a rooted phone, a compromised device or a man-in-the-middle position
- Best-practice recommendations, theory-level risks and copies of known issues
Rules of engagement
- First valid report wins. We pay nothing for duplicates or for issues we already knew about. Only one payment for each root cause, even if it affects many endpoints.
- Prove it, then stop. Access only your own accounts and data. Stop at the first proof and report if a test would expose someone else's data, and do not pivot, download or persist.
- Do not degrade the service. You may not load test, fuzz automatically at volume, or test proxy gateways, modem hosts or carrier networks. Those are out of scope entirely.
- Give us time. Publishing has to wait for our fix and for 30 days to pass. We tell you when the fix is out.
- Severity is ours to set. We look at impact on our own systems and take the Bugcrowd Vulnerability Rating Taxonomy as the reference. We choose payment amounts at our discretion within the ranges above and send them by PayPal or USDT.
How to report
Email [email protected] with the subject Security report. Tell us the affected URL, which account you used, the exact steps to reproduce, and a proof of concept. We acknowledge reports within 5 business days and decide on severity within 10 business days.
Machine-readable contact details are at /.well-known/security.txt.
Send a reportPolicy last updated 2026-10-10.
