The Cross Industry
Safe Proxy Program
Securing our residential proxy ecosystem and protecting our SDK users is always our top priority. We highly value the work of the independent cybersecurity research community in helping us keep our partners, customers, and the internet as a whole, safe and compliant.
To drive the highest standard of cybersecurity across the proxy industry, Bright Data is proud to lead an unprecedented, industry-wide Bug Bounty Program. We are funding a dedicated reward program to expose and mitigate any cybersecurity vulnerabilities discovered not only in our own network, but across the leading residential proxy providers SDK network.
In-Scope Companies
This program currently covers cybersecurity research on the infrastructure, APIs, and SDKs of the leading residential networks. Eligible residential networks should meet the following minimum requirements:
- Minimum 3 years: of continuous, active commercial operations under a verified, registered corporate entity.
- A globally distributed pool consisting of no fewer than 1,000,000 (1 Million) active unique monthly IP addresses.
- Documented and verified availability in at least 90 countries.
- Public enterprise-grade service claims demonstrating comparable global scale.
- Clearly describe or mention their relevant SDK used to build the residential network, across any platforms or operating systems. An example of such relevant information about Bright Data’s network and SDK can be found at bright-SDK.com.
For the purpose of this bug bounty program, a Residential Proxy SDK means a software development kit, library, agent, embedded module, mobile SDK, desktop SDK, browser component, or device-side software package that enables an application, device, or end-user environment to participate in a residential proxy network.
VPN clients, CDN nodes, hosting services, cloud instances, and similar infrastructure, as well as SDKs, wrappers, forks, sample libraries, or artificial integrations created primarily to obtain eligibility under this bounty program, are excluded from this program.
Rewards
Eligible, in-scope vulnerability reports may be evaluated for a potential financial reward. Any reward, if granted, will be determined at Bright Data’s discretion based on factors such as the validity, severity, impact, and quality of the report. Stay tuned for details.
How to Report a Vulnerability
For more information on The Cross Industry Safe Proxy Program, or If you believe you have discovered a security vulnerability in the network infrastructure, APIs, or SDKs of any participating eligible proxy provider, please let us know immediately at [email protected]. Final participation rules, eligibility criteria, scope, and submission procedures will be published before the program begins.
Program Guidelines
To encourage good-faith security research, we ask that you always respect the users and their systems. Please follow these core guidelines:
- No disruptions: Do not perform volumetric testing, DDoS attacks, or any tests that degrade the performance of the relevant services.
- Respect privacy: Do not access, modify, or destroy customers or SDK users’ data. If you encounter user data, stop and report it immediately.
- Keep it confidential: Do not publicly disclose your findings until the affected company has confirmed the vulnerability is patched.