Report Security Issues
If you have found a security vulnerability on urdevgo.com, operated by NAVY REEVES 2025 LLC, we encourage you to contact us immediately. We review all legitimate reports and aim to resolve reported issues promptly. Before submitting a report, please review this document, including our fundamentals, bounty program, reward guidelines, and non-reportable issues.
Fundamentals
If you follow the principles below when reporting a security issue to urdevgo.com, we will not initiate legal action or enforcement investigations against you in response to your report.
We ask that:
- You give us reasonable time to review and resolve the issue before disclosing it publicly or sharing it with others.
- You do not interact with or access private accounts without the account owner's consent.
- You make a good-faith effort to avoid privacy violations, service disruptions, or data destruction.
- You do not exploit the issue for any reason, including demonstrating additional risks or accessing sensitive data.
- You comply with all applicable laws and regulations.
Bounty Program
We recognize and may reward security researchers who help protect our platform by responsibly reporting vulnerabilities. Bounties are awarded at the sole discretion of NAVY REEVES 2025 LLC based on the risk, impact, severity, and quality of the report.
To potentially qualify for a bounty, you must:
- Follow the fundamentals listed above.
- Report a valid security vulnerability that poses a genuine risk to privacy or security.
- Submit your report through our designated security contact. Please do not contact employees directly.
- Disclose any accidental privacy violations, data access, or service disruptions in your report.
- Understand that although we investigate valid reports, reports are prioritized according to their risk and potential impact.
- Agree that we reserve the right to publish or disclose submitted reports after the vulnerability has been resolved.
Rewards
Rewards are based on the impact and severity of the vulnerability. Please provide detailed and reproducible steps in your report. Issues that cannot be reproduced are not eligible for a bounty.
- The first valid report of an issue may receive the bounty.
- Multiple vulnerabilities caused by the same underlying issue may be treated as one report.
- We assess rewards based on severity, impact, exploitability, and report quality.
- The following are our current maximum reward amounts by severity:
Critical Severity – $200
Examples may include:
- Remote code execution
- Remote shell or command execution
- Vertical authentication or authorization bypass
- SQL injection resulting in the disclosure of sensitive data
- Complete unauthorized account access
High Severity – $100
Examples may include:
- Horizontal authentication or authorization bypass
- Disclosure of sensitive internal data
- Stored cross-site scripting affecting other users
- Local file inclusion
- Insecure handling of authentication cookies
Medium Severity – $50
Examples may include:
- Logic or business-process vulnerabilities
- Insecure direct object references
Low Severity – Recognition Only
Examples may include:
- Open redirects
- Reflected cross-site scripting
- Low-sensitivity information disclosures
Contact Information
📍 Address: 1001 Carolina Pines Drive, Blythewood, SC 29016-7786, UNITED STATES
✆ Phone: +1 (667) 294-3282
✉ Email: contact@urdevgo.com
🕐 Business Hours
Mon – Fri: 9:00 AM – 6:00 PM
Saturday: 10:00 AM – 4:00 PM
Sunday: Closed
```