Bug Bounty Program Terms and Conditions
Updated Date:
Last updated: June 17, 2026
These Bug Bounty Program Terms and Conditions (“Terms”) cover your participation in the Bug Bounty Program (“Program”). These terms between you and Wonderful Systems Ltd. (“Wonderful”, “us” or “we”) govern your participation in the Program. By submitting any vulnerabilities to Wonderful or otherwise participating in the Program in any manner, you accept these Terms, you hereby represent and warrant that you have read, understood, and agree to be bound by these Terms.
Program Overview
The Program enables you to submit vulnerabilities and exploitation techniques (“Vulnerabilities”) to Wonderful about eligible Wonderful services, systems and offerings (“Offering”) for a chance to earn rewards in an amount determined by Wonderful in its sole discretion (“Bounty”). The decisions made by Wonderful regarding Bounties are final and binding.
Changes to These Terms or Program
Wonderful may change or cancel these Terms at any time, for any reason. Participating in the Program after the changes become effective means that you agree to the new Terms. If you don’t agree to the new Terms, you must not participate in the Program. If you wish to opt-out of the Program and not be considered for Bounties, contact us at security@wonderful.ai. Opting out will not affect any licenses granted to Wonderful in any Submissions (as defined below) provided by you.
1. Eligibility
You must meet the following criteria in order to be eligible to participate in the Program:
You must be either the legal age of majority in your country or at least 14 years of age with permission from your legal guardian that you may participate in the Program; and
You are either an individual researcher participating in your own individual capacity, or you work for an organization that permits you to participate. You are responsible for reviewing your employer’s rules for participating in this Program. Specifically, you are not violating any other agreement (i.e. employment agreement) to which you may be a party — we are not liable for any breach of such third-party agreement by you and disclaim any knowledge of or responsibility for your conduct; and
You are not subject to any sanctions or a resident of a country listed under a US, Swiss, European Union, or United Nations embargo or sanctions list.
Wonderful employees, contractors or representatives, or a family member of a Wonderful employee, contractor or representative, are not eligible to participate in the Program during the term of engagement with Wonderful and for a period of twelve (12) months following the termination of such engagement.
Wonderful reserves the right to disqualify any participant. Participation and the awarding of Bounty in our sole discretion may be subject to additional eligibility criteria.
If you are a public sector employee (government and education), all Bounties must be awarded directly to your public sector organization and subject to receipt of a gift letter signed by your organization’s ethics officer, attorney, or designated executive, officer responsible for your organization’s gifts, ethics policy. Wonderful seeks to ensure that by offering Bounties under this Program, it does not create any violation of the letter or spirit of a participant’s applicable gifts and ethics rules.
2. How to Participate
Each Vulnerability submitted to Wonderful shall be referred to herein as a “Submission”. Submissions must be submitted to security@wonderful.ai. In the initial email, the subject line of your email must be “Bug Bounty Submission”, and it must specify the Vulnerability details. Please also include as much of the following information as possible:
Type of issue;
Product or URL;
Step-by-step instructions to reproduce the issue;
Proof-of-concept or exploit code;
Impact of the issue, including how an attacker could exploit the issue.
Depending on the details of your Submission, Wonderful may award a Bounty of varying scales. Those Submissions that do not meet the minimum requirements described above are considered incomplete and not eligible for Bounties. There are no restrictions on the number of qualified Submissions you can provide and potentially receive a Bounty.
If you submit a Vulnerability for an Offering that is not covered by the Program at the time of submission, you will not be eligible to receive Bounty payments if the product or service is later added to the Program.
3. Submission License
By providing any Submission to Wonderful, you: (1) grant Wonderful the following non-exclusive, irrevocable, perpetual, royalty-free, worldwide, sublicensable license to the intellectual property in your Submission: (i) to use, review, assess, test, and otherwise analyze your Submission; (ii) to reproduce, modify, distribute, display and publicly perform, and commercialize and create derivative works of your Submission and all its content, in whole or in part; and (iii) to feature your Submission and all of its content in connection with the marketing, sale, or promotion of this Program or other programs (including internal and external sales meetings, conference presentations, tradeshows, and screenshots of the Submission in press releases) in all media (now known or later developed); (2) agree to sign any documentation that may be required for us or our designees to confirm the rights you granted above; and (3) understand and acknowledge that Wonderful may have developed or commissioned materials similar or identical to your Submission, and you waive any claims you may have resulting from any similarities to your Submission.
You represent and warrant that your Submission is your own work, that you have not used information owned by another person or entity, and that you have the legal right to provide the Submission to Wonderful.
YOU HEREBY UNDERSTAND THAT YOU ARE NOT GUARANTEED ANY COMPENSATION OR CREDIT FOR USE OF YOUR SUBMISSION.
4. Submission Review Process
Following the Submission, Wonderful team will review the Submission and validate its eligibility. The review time will vary depending on the complexity and completeness of your Submission, as well as on the number of Submissions we receive.
Wonderful retains sole discretion in determining which Submissions are qualified. If we receive multiple bug reports for the same issue from different parties, the Bounty will be granted to the first eligible Submission. If a duplicate report provides new information that was previously unknown to Wonderful, we may award a differential Bounty to the person submitting the duplicate report.
If you report a Vulnerability without a functioning exploit, you may be eligible for a partial Bounty.
5. Bounty Amounts
The following categories represent potential maximum award ranges only and do not create any obligation to award a Bounty in any specific amount:
Critical Severity: up to 10,000 USD
High Severity: up to 6,000 USD
Medium Severity: up to 1,500 USD
Low Severity: up to 200 USD
Actual Bounty amounts, if any, will be determined by Wonderful in its sole and absolute discretion.
6. Bounty Payment
If we have determined that your Submission is eligible for a Bounty, we will notify you of the Bounty amount and provide you with the necessary paperwork to process your payment where applicable. You may waive the payment if you do not wish to receive a Bounty.
We will require the following information in order to process a Bounty payment: name, address, phone number, email address, wire information, and any other required information as requested by Wonderful.
Bounty payouts are paid in United States Dollars and shall be sent using the details you provide us. Wonderful is not responsible for any inability to accept or receive a Bounty for any reason. We are not able to issue Bounty to participants who are in violation of a material term of these Terms.
Any applicable taxes and other costs and expenses associated with Bounty acceptance or receipt will be your sole responsibility. No more than the stated Bounty will be awarded. Wonderful will not replace any lost or stolen Bounty or any Bounty that is undeliverable because of an incorrect or changed address or contact information. If you do not accept the entire Bounty, the unaccepted part of the Bounty will be forfeited, and Wonderful will have no further obligation with respect to that Bounty or portion of the Bounty.
You are strictly prohibited from selling, auctioning, trading, or otherwise transferring your entitlement to a Bounty. Wonderful may be unable to make Bounty payments (for example, if prevented by a government or regulatory agency), impractical (e.g. excessive transfer costs, duties, or taxes), or if it is impossible for Wonderful to award if you live in certain jurisdictions. Wonderful reserves the right, but not the obligation, to cancel the payment of such Bounty in such circumstances.
7. Notifications
Notifications in connection with a Submission, Bounty, and your participation in the Program will be made by email using your email address provided. It is your sole responsibility to receive and monitor those methods to timely receive, review, and respond as needed to notifications. Failure to timely respond or complete any of the steps set forth in the notification for any reason, or failure to notice or accept a communication from Wonderful or its representative, may result in disqualification from receiving the Bounty. Wonderful reserves the right to contact you for verification purposes and administration of the Program. All Wonderful’s decisions are final and binding in all matters relating to the Program.
All notices provided to Wonderful in relation to the Program shall be sent to security@wonderful.ai.
8. Intellectual Property Rights
We retain all intellectual property rights in our Offering including, without limitation, our source code and associated related binaries, etc. Nothing herein shall grant you any right in any part of our products, or any improvement or derivative of any Submission you provide us. You agree that to the extent required to abide by these Terms, you will waive any and all rights that may otherwise accrue to you in any Submission and agree that we will not be obliged to license back any derivative or improvements of any Submission to you.
9. Indemnification; Limitation of Liability
You agree to be liable for and indemnify Wonderful, its subcontractors, and their respective directors, officers, and representatives (“Wonderful Indemnitees”) against any losses that Wonderful Indemnitees may incur arising from your breach of these Terms, including losses arising from gross negligence, willful misconduct, and breach of law.
In no event will Wonderful be liable to you for any loss of use, revenue or profit or loss of data or for any consequential, incidental, indirect, exemplary, special, aggravated, or punitive damages whether arising out of breach of contract, tort (including negligence) or otherwise, regardless of whether such damage was foreseeable and whether or not Wonderful had been advised of the possibility of such damages.
Notwithstanding anything else set out in these Terms, if liability exclusion is not enforceable under applicable law, our cumulative liability to you under these Terms (apart from payment of any Bounty to which you may be entitled) shall be one hundred dollars ($100.00). You further waive all rights to have damages multiplied or increased.
10. No Warranties
WONDERFUL, AND OUR AFFILIATES, RESELLERS, DISTRIBUTORS, AND VENDORS, MAKE NO WARRANTIES, EXPRESS OR IMPLIED, GUARANTEES OR CONDITIONS WITH RESPECT TO THE PROGRAM. YOU UNDERSTAND THAT YOUR PARTICIPATION IN THE PROGRAM IS AT YOUR OWN RISK. TO THE EXTENT PERMITTED UNDER APPLICABLE LAW, WE EXCLUDE ANY IMPLIED WARRANTIES IN CONNECTION WITH THE PROGRAM.
11. Confidentiality of Submissions
We attempt to address each Vulnerability Submission in a timely manner. While we are doing so, we require that Bounty Submissions remain confidential and cannot be disclosed to third parties. You may make available high-level descriptions of your research and non-reversible demonstrations after the Vulnerability is fixed. We require that detailed proof-of-concept exploit code and details that would make attacks easier on customers be withheld for 30 days after the Vulnerability is fixed. Wonderful will notify you when the Vulnerability in your Submission has been fixed. You may be paid prior to the fix being released and payment should not be taken as a notification of fix completion. If you impose a fixed timeline at any time throughout the process, you will forfeit your Bounty eligibility. Violations of this Section could require you to return any Bounties paid and disqualify you from future participation in the Program.
12. Code of Conduct
For you to participate in the Program, we require that you:
Meet the eligibility requirements.
Do not violate any applicable laws or regulations.
Do not violate the privacy of other users and not engage in actions to cause disruptions to others, including (but not limited to) unauthorized access to or destruction of data.
Do not share content that is offensive, inappropriate, graphic, or spam.
Do not harm (by planting vulnerability or introducing a virus or threat) or defraud Wonderful or its users during your research; you should make a good faith effort to not interrupt or degrade our services.
Do not target our physical security measures (attempts against Wonderful property or data centers), or attempt to use social engineering, spam, or distributed denial of service (DDOS) attacks.
Do not exploit a Vulnerability except as necessary for responsible testing and reporting.
Do not infringe upon the rights of others (e.g., unauthorized sharing of copyrighted material) or engage in activity that violates the privacy of others.
Report Vulnerabilities only to us and not to anyone else. Do not publicly disclose Vulnerabilities until they have been addressed by Wonderful.
Do not act in bad faith to fraudulently obtain a Bounty, including misrepresenting your identity, or submitting knowingly false Submissions.
Do not damage or cause interruption of the Program and/or prevent others from participating in or engaging in the Program.
Comply with these Terms.
If you violate these Terms, you may be prohibited from participating in the Program in the future and any Submissions you have provided may be deemed to be ineligible for Bounty payments.
13. Governing Law
This Program, these Terms, and any dispute arising under or related thereto (whether for breach of contract, tortious conduct, or otherwise) will be governed, construed, and interpreted under the laws of the State of Israel, without reference to or giving effect to its conflicts of law rules. Any legal actions, suits, or proceedings related to this Program (whether for breach of contract, tortious conduct, or otherwise) will be brought exclusively in the courts of Tel-Aviv, Israel. You hereby irrevocably accept, submit, and consent to the exclusive jurisdiction and venue of these courts with respect to any legal actions, suits, or proceedings arising out of or related to this Program.
Except where prohibited, as a condition of participating in this Program, you agree that between the parties, any and all disputes, claims, and causes of action arising out of or connected with this Program, or the Bounty awarded must be resolved individually, without resort to any form of class action.