Yarbo Bug Bounty Program Terms
Version: v1.0 | Effective Date: [07/24/2026] | Yarbo Security Center Issued by: Yarbo International Inc. (collectively “Yarbo”, including all direct and indirect subsidiaries, affiliated entities)
1.Project Overview
1.1 Program Nature and Contractual Relationship
This Yarbo Bug Bounty Program (the “Program”) constitutes a binding unilateral offer extended by Yarbo to security researchers (“Researchers”). A Researcher’s voluntary submission of any vulnerability report to Yarbo’s designated security mailbox constitutes the Researcher’s express, unconditional acceptance of all Program terms and conditions, which immediately forms a legally binding unilateral contract between Yarbo and the submitting Researcher.
Researchers shall not be required to remit any fees, charges or consideration to Yarbo for participation. Nor shall Yarbo provide Researchers with any fixed monthly or hourly remuneration solely for participating in the Program. Nothing contained herein shall create an employment relationship, partnership, joint venture, or agency relationship between Yarbo and any Researcher.
Yarbo reserves its sole and absolute right to amend, suspend, or terminate the Program at any time, provided written advance notice of no fewer than fourteen (14) calendar days is published on Yarbo’s official Security Center webpage: Yarbo Security Center. All vulnerability reports submitted and pending formal review prior to the effective date of any Program modification, suspension or termination shall be evaluated, adjudicated and compensated exclusively under the Program Terms in effect as of the date the relevant report was submitted.
1.2 Program Scope
The Program is designed to strengthen the cybersecurity posture of all Yarbo products, cloud infrastructure and online services through collaboration with the global security research community. Yarbo welcomes Researchers to submit credible, reproducible security vulnerabilities discovered within Yarbo’s in-scope assets; Yarbo shall provide formal acknowledgment and monetary bounty awards for all confirmed valid vulnerabilities in accordance with Section 5.
In-Scope Asset Categories
| Asset Category | Scope Description |
| Domain & Web Services | All globally operated official websites, cloud platforms, API service endpoints and business interfaces hosted within Yarbo’s proprietary domain namespace, including all subdomains and service endpoints falling under the yarbo.com root domain. |
| Mobile Applications & OTA Services | Yarbo native mobile applications for iOS and Android operating systems; all official Yarbo over-the-air (OTA) firmware delivery pipelines. |
| Hardware Devices & Firmware | All Y-Series and M-Series Yarbo robotic devices, plus all device firmware builds actively maintained and distributed by Yarbo as of the report submission date. |
| Cloud & IoT Backend APIs | Yarbo cloud management platform, Yarbo IoT gateway infrastructure, and Yarbo end-user identity authentication and authorization services. |
Excluded Assets & Testing Activities
The following assets and attack vectors are categorically excluded from Program coverage, whether or not individually enumerated herein:
-
Third-party hosted subdomains and external platforms: help centers, system status dashboards, community forums, corporate blogs, career recruitment portals, and independent third-party marketplace integrations. Any vulnerabilities affecting these external services must be reported directly to the respective platform operator, not Yarbo.
-
Non-production environments: development, staging, test, user acceptance testing (UAT), and all pre-release staging environments not designated for live customer use.
-
Embedded third-party authentication and payment gateways: security flaws within Google Sign-In, Apple ID Login, Stripe, PayPal or other external payment/authentication providers are the sole liability of the third-party service vendor.
-
Non-Yarbo operated domains: authorized reseller websites, partner landing pages, discontinued legacy products, and retired domain names no longer covered under Yarbo’s active security maintenance lifecycle.
-
Low-impact attack vectors lacking verifiable material adverse impact: Denial-of-Service (DoS/DDoS) flooding, social engineering and phishing campaigns, cosmetic compliance gaps without functional exploitability (e.g., missing HTTP security headers, incomplete cookie flag configurations), and raw automated scanner output submitted without a working, non-destructive Proof of Concept (PoC).
1.3 Eligibility Restrictions
The following individuals are ineligible to participate in the Program and shall not receive bounty awards for any submitted vulnerabilities:
-
Current full-time, part-time, temporary Yarbo employees, plus all interns engaged by Yarbo within the immediately preceding twelve (12) calendar months;
-
Third-party contractors directly engaged to develop, maintain or audit Yarbo security products or backend infrastructure, as well as such contractors’ own employees and subcontractors;
-
Immediate family and household members of the persons described above (including spouses, parents, children, and full/half siblings);
-
Any individual listed on U.S. federal, international or multilateral government sanctions lists, or residing within a jurisdiction subject to U.S. export control regulations;
-
Minors under eighteen (18) years of age, or persons below the statutory age of majority required under the laws of their country/region of domicile (such individuals lack full legal capacity to enter binding contracts under this Program).
Each Researcher hereby represents and warrants that, as of the date of vulnerability report submission, none of the above eligibility prohibitions apply to them. The Researcher shall bear sole, full legal liability for all damages, penalties, regulatory fines and legal costs arising from any material breach of this eligibility representation.
1.4 Vulnerability Submission Mandatory Requirements
Complete, high-fidelity vulnerability reports accelerate Yarbo’s security assessment workflow and streamline bounty adjudication. All submissions must include every element listed below:
-
Detailed, plain-language narrative description of the root cause and security flaw;
-
Linear, step-by-step reproduction instructions allowing Yarbo’s security team to replicate the vulnerability consistently;
-
Non-destructive Proof of Concept (PoC) code or demonstration (example: for Remote Code Execution (RCE) flaws, execute a harmless command such as
echo "security test"with no destructive file/resource manipulation); -
Full testing environment configuration details;
-
Affected URLs, mobile application identifiers, and relevant code snippets;
-
Exact hardware device model and targeted firmware version number;
-
Supporting testing artifacts: unaltered screenshots, log captures and network traffic recordings, attached to the formal report;
-
Formal impact assessment outlining the number of potentially affected end users and the risk scope of personal or sensitive data exposure.
* Failure to furnish all foregoing supporting materials in full may cause indefinite delays in vulnerability triage, and Yarbo reserves its sole and absolute right to reduce, withhold or fully deny any bounty award as a direct consequence of incomplete submissions.
Validity Standards for a Qualified Vulnerability Report
A submission shall only qualify as a valid bounty-eligible report if all of the following criteria are met concurrently:
-
The vulnerability resides within the Program’s defined in-scope asset list and does not fall under any exclusion outlined in Section 1.2;
-
The vulnerability remains unlogged, undisclosed and unaddressed within Yarbo’s internal vulnerability tracking systems as of the report submission timestamp;
-
The report contains fully reproducible step-by-step instructions paired with a non-destructive PoC demonstration;
-
The submitting Researcher has fully complied with all binding provisions of this Program document.
Handling Concurrent Duplicate Vulnerability Reports
-
The exact submission timestamp logged within Yarbo’s internal vulnerability intake system shall serve as the exclusive, conclusive record for determining priority of discovery for identical flaws;
-
If two substantially identical vulnerability reports are filed within forty-eight (48) hours of one another, Yarbo may, in its sole and absolute discretion, allocate no less than fifty percent (50%) of the base bounty tier amount to each submitting Researcher;
-
This concurrent reporting allocation framework applies on a case-by-case basis only and shall not establish a binding precedent for future duplicate submissions.
Yarbo shall send formal written acknowledgment of report receipt within seven (7) business days following submission, and complete an initial severity tier classification within fifteen (15) business days, delivering a written preliminary determination notice to the submitting Researcher via email.
2.Vulnerability Severity Classification Standards
All confirmed vulnerabilities shall be assigned one of four hierarchical severity tiers: Critical, High, Medium, Low. Yarbo’s security team shall weigh the following material risk factors exclusively when assigning severity rankings:
-
Volume and sensitivity of user data susceptible to unauthorized exposure;
-
Technical ease of exploitation with minimal preconditions;
-
Probability of material harm to Yarbo end users and overall business risk exposure;
-
Total scope of impacted Yarbo web infrastructure, cloud services or physical devices.
The following criteria shall not be considered for severity tier assignment under any circumstance:
-
Total time the Researcher invested to identify the flaw;
-
Out-of-pocket costs incurred by the Researcher to purchase Yarbo hardware or access paid testing tools;
-
Vulnerabilities already logged and tracked within Yarbo’s internal remediation backlog prior to submission;
-
All other subjective metrics that cannot objectively quantify functional exploit risk or user harm.
3.Web System Vulnerability Classification Guidelines
3.1 Critical Severity
| Vulnerability Type | Formal Description |
| Remote Code Execution (RCE) | Unauthenticated arbitrary operating system command execution on Yarbo web or cloud servers. |
| Core Database SQL Injection | Bulk extraction of high-sensitivity core user records including login credentials, account passwords, payment card and billing information. |
| Full Authentication Bypass | Complete circumvention of identity verification workflows to grant unrestricted access to any arbitrary user account. |
| Mass Data Exposure Incident | Unauthorized export of more than ten thousand (10,000) unique sensitive user records in a single exploit chain. |
| Supply Chain Attack Surface | RCE within CI/CD build pipelines or unauthorized tampering of official release build artifacts. |
3.2 High Severity
| Vulnerability Type | Formal Description |
| Non-Core Database SQL Injection | Extraction of non-core but commercially sensitive business or user metadata. |
| Arbitrary File Read | Unauthorized access to server-side confidential configuration files or proprietary source code repositories. |
| Vertical Privilege Escalation | Ability to elevate standard authenticated user permissions to full administrative access. |
| SSRF with Internal Network Reach | Server-Side Request Forgery enabling scanning of private internal network hosts and cloud metadata service endpoints. |
| Financial/Order Race Condition | Manipulation of promotional credit limits, repeated unauthorized offer redemption, or alteration of customer order monetary values. |
| Limited Mass Data Exposure | Unauthorized export of one thousand (1,000) to ten thousand (10,000) non-core user records. |
| Unsafe Deserialization | Triggerable deserialization vulnerability without direct remote code execution capability. |
3.3 Medium Severity
| Vulnerability Type | Formal Description |
| Persistent (Stored) XSS | Cross-Site Scripting allowing persistent session hijacking or unauthorized state modification on behalf of logged-in users. |
| Restricted SSRF | Server-Side Request Forgery limited to a narrow subset of internal network resources with no lateral movement risk. |
| Material Business Logic Flaw | Circumvention of platform business guardrails with contained, non-systemic impact. |
| Non-Sensitive Information Disclosure | Exposure of internal server file paths, software version strings, or unauthenticated debug administration interfaces. |
| Critical-Function CSRF | Cross-Site Request Forgery enabling alteration of core account settings such as registered email addresses or login passwords. |
| Minor Data Exposure | Unauthorized export of fewer than one thousand (1,000) low-sensitivity non-core user records. |
3.4 Low Severity
| Vulnerability Type | Formal Description |
| Reflected XSS | Cross-Site Scripting requiring targeted end-user interaction with limited exploit impact scope. |
| Non-Critical CSRF | Cross-Site Request Forgery modifying cosmetic user preference settings with no security risk. |
| Low-Sensitivity Information Disclosure | Verbose stack trace error messages exposed to unauthenticated visitors. |
| Open Redirect | Server-side redirection to untrusted third-party external domains. |
| Restricted CORS Misconfiguration | Cross-origin resource sharing gaps permitting limited read-only access to low-risk endpoints. |
| Read-Only Unauthorized API Endpoint | Unprotected API routes exposing only publicly available or negligible-sensitivity data. |
4.Device & Mobile Application Vulnerability Classification Guidelines
4.1 Critical Severity
| Vulnerability Type | Formal Description |
| Unauthenticated Remote Unsigned Firmware Flashing | Remote deployment of malicious custom firmware granting complete root control over targeted hardware devices. |
| Remote Device Takeover Endangering Physical Safety | Remote manipulation of robotic device motion and locomotion systems creating foreseeable risk of bodily injury to end users. |
| Secure Boot Bypass | Circumvention of hardware secure boot mechanisms to execute untrusted, unsigned binary firmware images. |
| Mass Fleet Remote Compromise | Exploit capable of remotely seizing administrative control of more than one thousand (1,000) connected Yarbo devices simultaneously. |
| Hardware Root of Trust (RoT) Compromise | Extraction or forgery of the unique cryptographic device identity root key embedded in hardware secure enclaves. |
4.2 High Severity
| Vulnerability Type | Formal Description |
| Local Root Privilege Escalation | Privilege elevation from restricted shell access to full root administrative permissions on the device operating system. |
| Single-Device Remote Full Takeover | Remote complete administrative control of an individual Yarbo device (no mass fleet compromise capability). |
| Individual User PII Breach | Remote unauthorized access to a single user’s geolocation logs and device task scheduling data. |
| Bluetooth/Wi-Fi Radio Protocol Exploit | Wireless protocol flaw enabling device hijacking within physical communication proximity. |
| Compromisable OTA Update Pipeline | Interception, modification or forgery of official signed OTA firmware update packages in transit. |
4.3 Medium Severity
| Vulnerability Type | Formal Description |
| Device Metadata Disclosure | Unauthorized extraction of internal firmware build versions, unique serial numbers, connected Wi-Fi SSID names and device hardware identifiers. |
| Partial Communication Encryption Weaknesses | Cryptographic flaws allowing partial decryption of device-to-cloud transmitted data streams. |
| Unencrypted Local On-Device User Data | Sensitive user information stored unencrypted within persistent local device storage. |
| Mobile App Local Data Leakage | Unencrypted sensitive credentials or user metadata cached locally within the Yarbo iOS/Android mobile application. |
| Restricted Device Function Control | Unauthorized manipulation of non-safety-critical device features (e.g., speaker audio, LED lighting indicators). |
| Remote Device Denial of Service | Remote exploit rendering a target device unresponsive or non-functional. |
| App Backend Authentication Flaw | Mobile-to-cloud API authentication vulnerable to replay attacks or request tampering. |
4.4 Low Severity
| Vulnerability Type | Formal Description |
| Physical Local Denial of Service | DoS condition requiring direct physical contact with the hardware device to trigger forced reboot. |
| Exposed Hardware Debug Interfaces | Unlocked UART/JTAG debug ports accessible only via device physical disassembly. |
| Negligible Information Disclosure | Exposed device runtime logs and debug diagnostic output with no sensitive user or cryptographic material. |
| Missing Mobile App SSL Certificate Pinning | Mobile application lacking TLS certificate pinning defenses against man-in-the-middle interception. |
| Bluetooth Broadcast Data Leakage | Unintended exposure of device MAC hardware address or public device name over unencrypted Bluetooth advertising frames. |
5.Reward Standards
5.1 Base Bounty Tier Amounts (USD)
All monetary figures listed below represent gross pre-award U.S. dollar compensation ranges, split by asset category and severity sub-tier:
| Severity Tier | Web System Asset Range | Device / Mobile Application Asset Range |
| Critical III | Eleven Thousand ($11,000) – Thirteen Thousand ($13,000) | Thirteen Thousand ($13,000) – Fifteen Thousand ($15,000) |
| Critical II | Eight Thousand Five Hundred ($8,500) – Ten Thousand ($10,000) | Ten Thousand ($10,000) – Twelve Thousand ($12,000) |
| Critical I | Five Thousand Five Hundred ($5,500) – Six Thousand Five Hundred ($6,500) | Seven Thousand ($7,000) – Eight Thousand ($8,000) |
| High III | Three Thousand Five Hundred ($3,500) – Four Thousand ($4,000) | Four Thousand Five Hundred ($4,500) – Five Thousand ($5,000) |
| High II | Two Thousand ($2,000) – Two Thousand Five Hundred ($2,500) | Two Thousand Five Hundred ($2,500) – Three Thousand ($3,000) |
| High I | One Thousand Two Hundred ($1,200) – One Thousand Five Hundred ($1,500) | One Thousand Five Hundred ($1,500) – One Thousand Eight Hundred ($1,800) |
| Medium II | Five Hundred ($500) – Eight Hundred ($800) | Seven Hundred ($700) – One Thousand ($1,000) |
| Medium I | Two Hundred ($200) – Three Hundred ($300) | Two Hundred ($200) – Four Hundred ($400) |
| Low (Single Uniform Tier) | One Hundred ($100) | One Hundred Fifty ($150) |
5.2 Tier Bounty Adjustment Weighting Factors
Yarbo’s security team shall adjust the final bounty value within the assigned severity tier range based on the following ordered weighting criteria (higher-weight factors increase final award value):
-
Exploit Authentication Barrier: Unauthenticated exploitation > exploitation requiring standard user account login > exploitation dependent on rare, restrictive preconditions;
-
End User Impact Scope: All platform users vulnerable > segmented subset of users vulnerable > exploit limited to narrow edge-case usage scenarios;
-
Exposed Data Sensitivity: Payment/government identity data > geolocation and behavioral telemetry > non-sensitive public metadata;
-
Report Completeness: Full PoC + actionable production remediation guidance > complete reproduction steps only > high-level textual description without demonstration artifacts.
5.3 Eligible Supplementary Bonus Awards
| Scenario | Bonus Compensation Terms |
| Threat Intelligence Submission (Active threat actor TTPs, adversary group infrastructure research) | Base bonus of Five Hundred USD ($500); maximum supplemental award of Two Thousand USD ($2,000) for material high-risk threat intelligence. |
| Chained Multi-Vulnerability Exploit Chain | Additional thirty percent (30%) to fifty percent (50%) uplift applied to the aggregate combined base bounty of all linked individual flaws. |
| Annual Top 3 Outstanding Researcher Contribution Recognition | One Thousand USD ($1,000) to Three Thousand USD ($3,000) one-time annual bonus. |
| Submission of Fully Tested, Production-Grade Remediation Patch/Implementation Guidance | Twenty percent (20%) flat uplift added to the original base bounty tier award. |
5.4 Mandatory Preconditions for Bounty Disbursement
Yarbo shall not release any bounty payment unless all of the following conditions precedent are fully satisfied without exception:
-
Yarbo’s internal security team has issued formal written written confirmation validating the vulnerability as bounty-eligible;
-
The Researcher executes, signs and returns the Yarbo Bug Bounty Program Non-Disclosure Agreement (the “Program NDA”) furnished by Yarbo;
-
The Researcher submits fully complete, legally valid tax documentation matching their residency status (Form W-9 for U.S. tax residents; Form W-8BEN for all non-U.S. tax residents);
-
The Researcher has fully complied with every binding term and provision of this Program document from report submission through final bounty disbursement.
5.5 Circumstances Where Bounty Payment May Be Fully Withheld
Yarbo reserves its sole and absolute right to deny all bounty compensation to a Researcher under the below circumstances, and such withholding shall not constitute any material breach of this Program unilateral contract:
-
Yarbo independently discovered the identical vulnerability prior to the Researcher’s submission timestamp, or another Researcher filed a valid priority report covering the same flaw;
-
The submitted report fails to satisfy all validity requirements laid out within Section 1.4;
-
The Researcher materially violated any Program provision, including unauthorized system access, destructive testing operations, or premature public disclosure of unremediated vulnerabilities;
-
The Researcher falls under any eligibility prohibition defined within Section 1.3;
-
The Researcher provided materially false identifying information or submitted fabricated, non-existent vulnerabilities;
-
Yarbo had already launched active internal remediation workstreams targeting the documented vulnerability prior to the date of report submission.
Bounty payments shall also be fully denied for submissions falling into the following categorical exceptions:
-
Reports consisting solely of raw automated vulnerability scanner output without functional verified exploit demonstration;
-
Vulnerabilities corresponding to Common Vulnerabilities and Exposures (CVEs) already published to public global vulnerability databases prior to submission;
-
Flaws affecting assets excluded from the Program’s in-scope asset list in Section 1.2;
-
All testing activity violating the mandatory code of conduct in Section 8;
-
Social engineering campaigns, physical hardware destruction testing, and DoS/DDoS flooding attacks against Yarbo infrastructure or devices.
5.6 Payment Mechanism & Timing
All bounty awards are denominated in United States Dollars (USD). Disbursement shall be processed via wire transfer or PayPal within forty-five (45) business days following the date Yarbo issues formal written vulnerability validation. All applicable income taxes, foreign currency exchange conversion losses, cross-border bank intermediary fees and transaction charges shall be borne exclusively by the receiving Researcher. Yarbo shall comply with all mandatory statutory tax withholding obligations imposed by relevant local taxing authorities in applicable jurisdictions, with all withheld amounts deducted directly from the gross bounty award total.
6.Tax Liability Provisions
6.1 Applicable Tax Regime Determination
The tax compliance framework set forth in this Section 6 is governed by the legal entity responsible for issuing bounty payment:
-
If bounty compensation is disbursed by Yarbo’s United States corporate affiliate (the “U.S. Entity”), the rules contained within Section 6.2 shall apply in full;
-
If bounty compensation is disbursed by Yarbo’s People’s Republic of China corporate affiliate (the “China Entity”), the rules contained within Section 6.3 shall govern all withholding and reporting obligations. The exact paying corporate entity will be explicitly identified within the formal bounty award notification email delivered to the Researcher.
6.2 U.S. Entity Tax Compliance Rules
(A) Mandatory Withholding Tax Rules
The U.S. Entity shall calculate and withhold applicable federal income tax from bounty payments based on complete, valid Form W-9 or Form W-8BEN documentation submitted by the Researcher prior to disbursement. If a Researcher fails to furnish compliant tax paperwork before scheduled payment release, the U.S. Entity shall automatically withhold thirty percent (30%) of the gross bounty amount as default U.S. federal backup withholding tax without additional prior notice to the Researcher.
(B) Tax Treaty Reduced Withholding Claims
Any Researcher seeking reduced withholding tax rates under an applicable bilateral income tax treaty bears sole independent responsibility for verifying the accuracy of the treaty article citation and preferential tax rate they claim. All additional tax liabilities, monetary penalties and interest charges stemming from incomplete, incorrect or fraudulent treaty documentation submitted by the Researcher shall be the exclusive financial obligation of the Researcher. The U.S. Entity relies in good faith on all tax forms provided by the Researcher and shall not be held jointly or severally liable for reporting errors originating from the Researcher’s inaccurate filings.
(C) IRS Form 1099-NEC Mandatory Reporting
For U.S. tax resident Researchers, if the aggregate gross bounty compensation received from the U.S. Entity within a single calendar year reaches or exceeds Six Hundred USD ($600), the U.S. Entity shall file Form 1099-NEC with the U.S. Internal Revenue Service (IRS) per mandatory federal tax law requirements and deliver a duplicate copy to the Researcher. The Researcher bears full individual responsibility for reporting all bounty award income on their annual federal and state personal income tax filings.
(D) Obligation to Notify Tax Status Modifications
If a Researcher’s tax residency classification, tax filing status, or personal tax circumstances undergo any material change, the Researcher must deliver formal written notification to the U.S. Entity and submit updated compliant tax documentation within thirty (30) calendar days of the status change effective date. Any miscalculated tax withholding or erroneous IRS reporting arising from delayed or omitted status notification shall be the sole financial liability of the Researcher.
6.3 China Entity Tax Compliance Rules
(A) Statutory Withholding & Remittance Obligations
Pursuant to the Individual Income Tax Law of the People’s Republic of China, the China Entity, as the statutory paying withholding agent, shall deduct and remit individual income tax on all bounty compensation per mandatory PRC tax regulation. All bounty tier amounts listed within Section 5 represent pre-tax gross values; the net cash amount actually remitted to the Researcher shall equal the gross award less all statutorily required individual income tax withholdings.
(B) Income Classification & Statutory Tax Rate
All Program bounty compensation shall be categorized as income from incidental gains under current PRC individual income tax regulation, subject to a flat statutory withholding rate of twenty percent (20%). The China Entity reserves the right to adjust its tax withholding procedures to align with updated national tax legislation or official tax bureau regulatory mandates, and shall provide reasonable advance written notice to affected Researchers for any material procedural withholding changes.
(C) Accuracy of Submitted Banking & Identity Documentation
All legal names, government identification numbers, domestic or cross-border bank account routing details and supporting documentation submitted by the Researcher must be true, complete and factually accurate. Any failed tax remittance filings, incorrect withholding calculations or failed fund transfers directly attributable to erroneous information supplied by the Researcher shall be the exclusive financial responsibility of the Researcher.
6.4 Tax Advice Disclaimer
All tax withholding, reporting and remittance procedures outlined within this Section 6 are implemented in strict accordance with prevailing statutory tax laws and regulatory guidance in the relevant disbursement jurisdiction. Nothing contained within this Section shall be construed as formal tax, legal or financial advisory services directed to any Researcher. Individual tax filing obligations vary significantly based on the Researcher’s country of tax residence, annual total income volume and personal filing circumstances. All Researchers are strongly advised to retain independent licensed professional tax counsel to address jurisdiction-specific tax questions arising from Program bounty income.
7.Vulnerability Response & Remediation Timelines
Yarbo formally covenants to adhere to the following standardized security response service level agreements for all valid vulnerability reports:
-
Formal written receipt acknowledgment to Researcher: within seven (7) business days of report intake;
-
Complete initial vulnerability severity tier classification: within fifteen (15) business days of report intake;
-
Delivery of formal documented remediation implementation plan addressing the confirmed vulnerability: within thirty (30) business days following validation of a fully compliant bounty-eligible report.
8.Security Testing Code of Conduct
8.1 Safe Harbor Protections
Yarbo hereby agrees and covenants that for all security research activities fully satisfying every condition listed below, Yarbo shall refrain from filing civil claims against the Researcher and shall not report such activity to law enforcement authorities for potential criminal prosecution under the Computer Fraud and Abuse Act (CFAA), Digital Millennium Copyright Act (DMCA), or analogous cybersecurity statutes in any applicable jurisdiction:
-
All testing activity is strictly limited exclusively to the in-scope assets explicitly enumerated within Section 1.2 of this Program;
-
All research testing is conducted in good faith, without destructive system manipulation, and with no intent to obtain unlawful financial gain or competitive advantage over Yarbo;
-
The Researcher only accesses hardware devices, user accounts and testing environments they lawfully own, possess written authorization to audit, or that Yarbo explicitly provisioned for Program security testing purposes;
-
Immediately upon identifying a reproducible security vulnerability, the Researcher ceases all further exploit testing activity and submits a complete formal vulnerability report to Yarbo’s designated security intake mailbox;
-
The Researcher maintains strict confidentiality over all discovered vulnerabilities and refrains from disclosing any related technical details to any third party prior to receiving formal written public disclosure authorization from Yarbo.
This Safe Harbor provision shall not shield Researchers from civil or criminal liability arising from any testing activity explicitly prohibited within Section 8.3 of this Program. This Safe Harbor clause shall not restrict, bind or preempt any independent investigative or enforcement actions undertaken by external government law enforcement or regulatory authorities outside of Yarbo’s direct control.
8.2 Permitted Security Testing Activities
The following testing practices are authorized and covered under the Section 8.1 Safe Harbor protection framework, provided all other Program terms are satisfied:
-
Conducting non-destructive security auditing and vulnerability testing on Yarbo hardware devices lawfully owned by the submitting Researcher;
-
Executing limited, non-intrusive test payloads that do not degrade service availability or disrupt experience for live Yarbo end users;
-
Immediately discontinuing all exploit attempts upon successful reproduction and confirmation of a functional security vulnerability flaw.
8.3 Strictly Prohibited Testing Activities
All of the following actions are categorically forbidden under this Program; any confirmed violation shall result in immediate permanent disqualification from all future Program participation and may expose the Researcher to civil damages claims or criminal regulatory liability:
-
Unauthorized access, reading, mass downloading, modification or permanent deletion of any third-party user accounts, personal identifiable information (PII), or internal Yarbo employee data;
-
Launching DoS/DDoS flooding, traffic stress testing or resource exhaustion payloads that impair the operational availability of any Yarbo web, cloud or device backend system;
-
Bulk extraction, capture, local storage or retention of any Yarbo end-user personal data through automated scraping or exploit payloads;
-
Performing destructive hardware or firmware modification operations on any Yarbo device not fully owned by the Researcher;
-
Executing security testing against Yarbo hardware devices without prior explicit written testing authorization from an authorized Yarbo security representative;
-
Extracting confidential internal information via targeted social engineering campaigns including spoofed phishing email communications, employee identity impersonation, and pretexting;
-
Outsourcing all or any portion of vulnerability research testing work to external third parties, or collaborating on Program testing with individuals not bound to the full terms of this Program unilateral contract;
-
Filing identical or substantially identical vulnerability reports to competing third-party bug bounty platforms for separate monetary remuneration, absent prior written consent issued by Yarbo’s security team.
Mandatory Data Containment Response for Accidental PII Exposure
If a Researcher inadvertently accesses, retrieves or captures any Yarbo end-user personal identifiable information (PII) during authorized testing activity, the Researcher must execute all of the following corrective steps without delay:
-
Immediately terminate all further testing activity targeting the affected asset;
-
Permanently delete all captured PII data stored on local testing workstations, cloud storage or mobile devices;
-
Fully document the exact sequence of events leading to accidental PII exposure within the formal vulnerability report submitted to Yarbo.
9.Confidentiality & Controlled Vulnerability Public Disclosure
9.1 Binding Confidentiality Obligations
Each Researcher shall owe an unwavering strict duty of confidentiality with respect to all information defined below (collectively the “Confidential Information”):
-
Full text, artifacts and supporting evidence contained within the Researcher’s formal vulnerability report submission;
-
Yarbo proprietary internal system architecture, cloud network design and infrastructure topology documentation;
-
Yarbo production server IP addresses, internal private network routing schematics and firewall segmentation rules;
-
All proprietary Yarbo source code snippets, binary firmware logic and vulnerability remediation workarounds shared with the Researcher during triage;
-
All end-user personal identifiable information encountered during authorized security testing workflows.
No Researcher shall disclose, share, publish or transmit any Confidential Information to any external third party (including cybersecurity media outlets, public security research communities, or governmental regulatory bodies) unless one of the following triggering conditions is fully satisfied:
-
Yarbo delivers formal written authorization approving public disclosure of the vulnerability;
-
Yarbo publishes an official public remediation security advisory fully resolving the flaw, and a minimum of thirty (30) calendar days have elapsed following the advisory release date;
-
Mandatory disclosure is compelled by binding applicable local, state or federal statute, court order or regulatory subpoena (the Researcher shall provide formal advance written notification to Yarbo’s security team prior to any compelled statutory disclosure).
These confidentiality obligations shall survive any termination of the Program document or final administrative closure of the corresponding vulnerability report for a period of three (3) full calendar years from the report closure date. Any unauthorized access, mass download, reproduction or public dissemination of Yarbo proprietary source code or user personal data may constitute actionable civil or criminal misconduct under applicable global cybersecurity and data protection statutes, and Yarbo reserves all legal rights to pursue full remedies against violating Researchers.
9.2 Formal Vulnerability Public Disclosure Application Process
Any Researcher seeking Yarbo’s written approval to publish a vulnerability write-up or technical analysis must complete the following formal application workflow:
-
Complete Yarbo’s standardized Vulnerability Disclosure Request form and deliver the full document to security@yarbo.com via email;
-
Attach all complete supporting materials the Researcher intends to include within the planned public disclosure (blog posts, technical slides, PoC demonstration code, screenshots);
-
Yarbo’s security team shall initiate formal review upon receipt of a fully complete application package and issue written authorization upon internal approval.
No public disclosure may be published earlier than thirty (30) calendar days following Yarbo’s official release of a full production remediation patch resolving the confirmed vulnerability flaw.
All authorized public disclosures must comply with the following permanent content restrictions:
-
No raw or redacted end-user personal identifiable information may be included;
-
No production Yarbo server IP addresses, internal network segmentation schematics or private infrastructure topology details may be published;
-
No narrative, technical detail or imagery that foreseeably harms Yarbo’s legitimate commercial business interests or end-user data security may be included.
All vulnerability impact descriptions within authorized public disclosures must remain objective, factually accurate and technically precise. Researchers are prohibited from sensationalizing exploit risk, inciting user anxiety, or intentionally generating mass public panic regarding Yarbo product or cloud security posture. Reference to Yarbo’s full formal Vulnerability Disclosure Policy is permitted in approved public write-ups.
10.Intellectual Property License Terms
By submitting any vulnerability report, PoC demonstration code, supporting screenshots or technical analysis artifacts to Yarbo’s security intake mailbox, the submitting Researcher irrevocably grants Yarbo a worldwide, perpetual, royalty-free, non-exclusive commercial license to reproduce, modify, store, distribute and utilize all report content exclusively for internal vulnerability remediation engineering, periodic internal security auditing, and mandatory global regulatory compliance reporting purposes.
The underlying copyright of the vulnerability report original text and custom PoC demonstration code shall remain fully vested with the submitting Researcher. However, the Researcher shall not publish, distribute or monetize any commercial publication, paid training material or technical whitepaper incorporating Program vulnerability report content without prior written authorization issued by Yarbo’s authorized security representative.
Each Researcher hereby warrants and represents that all submitted vulnerability report materials, custom PoC code and supporting technical artifacts do not infringe upon any third-party copyright, patent, trade secret or trademark intellectual property rights, and contain no embedded malicious code, exploit payloads or destructive system manipulation logic.
11.Disclaimer & Limitation of Liability
This Program and all associated security research services are provided to Researchers on an “AS IS” and “AS AVAILABLE” basis. Yarbo disclaims all express, implied and statutory warranties of any kind, including without limitation all implied warranties of merchantability, fitness for a specific security research purpose, non-infringement and quiet enjoyment. Yarbo makes no guarantee, representation or warranty regarding the uninterrupted continued operation of the Program, bounty eligibility status for any specific vulnerability flaw, or minimum/maximum monetary bounty award value for any submitted report.
To the fullest maximum extent permitted under applicable controlling law, Yarbo shall not be held liable to any Researcher for indirect, special, incidental, exemplary, punitive or consequential damages, lost profits, lost business opportunity, or reputational harm arising from or connected to the Researcher’s participation in this Bug Bounty Program.
Yarbo’s total aggregate maximum cumulative liability to any single Researcher, regardless of the underlying legal theory of claim (contract, negligence, statutory violation or otherwise), shall not exceed the greater of (1) the total gross bounty award amounts actually disbursed by Yarbo to that Researcher under the Program, or (2) One Thousand United States Dollars ($1,000).
12.Personal Data Protection & GDPR Compliance
Yarbo shall collect, store, process and retain all personal identifying information submitted by Researchers during Program participation in full compliance with Yarbo’s official global Privacy Policy hosted at Privacy Policy. All personal data collection activities are limited exclusively to four defined legitimate business purposes: Researcher identity verification, cross-border bounty payment disbursement, mandatory domestic/international tax compliance recordkeeping, and ongoing administrative management of the Bug Bounty Program.
Mandatory personal data retention period: All Researcher identifying records shall be retained for five (5) full calendar years following the formal administrative closure date of the corresponding vulnerability report, solely to satisfy mandatory tax audit, regulatory recordkeeping and statutory compliance retention requirements.
For all Researchers domiciled within the European Economic Area (EEA), Yarbo commits to process all submitted personal data in strict alignment with the General Data Protection Regulation (GDPR). All EEA-based Researchers hold enforceable statutory data subject rights including the right of data access, right to rectification of inaccurate personal records, right to restriction of data processing, and right to data portability of all stored personal identifying information.
13.Dispute Resolution & Governing Law
This Program unilateral contract shall be governed by, construed and enforced exclusively under the substantive laws of the State of Delaware, United States of America, without application of any Delaware conflict-of-laws statutory principles that would redirect governing law to an alternative jurisdiction.
If any disagreement, claim or dispute arises between Yarbo and a Researcher connected in any manner to participation in this Program document, the parties shall first attempt informal amicable written negotiation for a period of thirty (30) calendar days. If no mutually acceptable resolution is reached within this thirty-day negotiation window, either party may initiate formal civil litigation in a competent state or federal district court located within the State of Delaware. Each Researcher irrevocably consents to the exclusive personal jurisdiction and venue of such Delaware courts, and fully waives all procedural objections including the doctrine of forum non conveniens.
Bounty Award Reconsideration Appeal Process
Any Researcher dissatisfied with Yarbo’s final written bounty eligibility or tier classification determination may submit a formal written reconsideration appeal request to security@yarbo.com within thirty (30) calendar days following the date of Yarbo’s final determination notice. Yarbo’s security team shall deliver a formal written reconsideration ruling within twenty (20) business days of receiving a complete appeal submission. Initiation of the internal reconsideration appeal workflow shall not toll, modify or restrict the Researcher’s underlying statutory right to pursue formal civil litigation under Delaware governing law.
All claims, grievances or legal disputes arising under this Program must be asserted by the Researcher on an entirely individual basis. Researchers are prohibited from pursuing any class action lawsuit, consolidated multi-claim arbitration, or representative collective litigation against Yarbo arising from Program participation. Each Researcher expressly waives all legal rights to join, participate in or recover compensation via any class-wide collective legal proceeding against Yarbo connected to this Bug Bounty Program.
14.Remedies for Material Program Term Breach
If a Researcher materially violates any binding provision contained within this Program document (specifically including all prohibited testing activities outlined within Section 8.3), Yarbo reserves all cumulative, non-exclusive remedies below:
-
Immediate permanent disqualification of the Researcher from all present and future Program participation eligibility;
-
Full withholding of all outstanding unpaid bounty awards, plus formal demand for full repayment of any bounty amounts previously disbursed to the violating Researcher;
-
Formal written reporting of the violating conduct to relevant domestic or cross-border government law enforcement and cybersecurity regulatory authorities;
-
Initiation of civil litigation and pursuit of all available criminal liability remedies permitted under applicable local, state and federal cybersecurity statutes.
If a Researcher’s material Program breach causes quantifiable financial loss, operational disruption or regulatory penalty to Yarbo or its end-user customer base, the violating Researcher shall bear full, unlimited compensatory liability for all resulting damages, including without limitation data restoration labor costs, system remediation engineering fees, all reasonable attorney’s fees, court filing costs, and all regulatory monetary fines levied against Yarbo due to the Researcher’s prohibited testing activity.
15.Severability & Entire Integration Clause
This complete Program document constitutes the full entire agreement between Yarbo and all participating Researchers concerning all terms governing the Yarbo Bug Bounty Program, and fully supersedes all prior oral discussions, informal written correspondence, draft terms or side agreements related to the same subject matter.
If any single provision contained within this Program document is adjudicated invalid, void or unenforceable by a court or arbitral tribunal of competent jurisdiction, the offending provision shall be reformed to the narrowest minimum scope required to render it legally enforceable under controlling applicable law. All remaining unaffected Program terms shall remain in full force and unmodified binding effect.
No delay, omission or failure by Yarbo to enforce any binding Program provision against a breaching Researcher shall constitute a permanent waiver of Yarbo’s contractual right to enforce that identical provision against any present or future Program participant.
16.Official Program Contact Information
| Inquiry Category | Designated Contact Channel |
| Vulnerability Report Submission | security@yarbo.com |
| Formal Public Disclosure Application Requests | security@yarbo.com |
| Yarbo Official Security Center Portal | Yarbo Security Center |
© 2026 Yarbo International Inc. All Rights Reserved.































Private group · 33.0K members