Programs/Northwind Cloud

Northwind Cloud

PublicManaged triage
Cloud infrastructure & developer platform · northwind.com

Northwind Cloud runs a public bug bounty program covering its production platform, public API and mobile apps. We reward valid, in-scope vulnerabilities by severity and aim to respond to every report within two business days.

Submit a report
Max bounty
$8,000
Avg. response
1.8 days
Reports resolved
118
Bounties paid
$214k
Researchers
42

Scope

In scope
*.northwind.comWeb
api.northwind.comAPI
Northwind iOS appMobile
Web dashboardWeb
Out of scope
status.northwind.com
Third-party marketing sites
Denial-of-service / volumetric
Social engineering & physical

Rewards by severity

SeverityExamplesBounty
CriticalRCE, auth bypass, mass data exposure$3,200 – $8,000
HighSSRF, stored XSS, privilege escalation$1,200 – $3,000
MediumIDOR, CSRF on sensitive actions$300 – $750
LowReflected XSS, minor info disclosure$60 – $150

Rules & policy

01

Test only assets listed in scope. Never access, modify or delete data that does not belong to your test account.

02

Use your own test accounts. Stop immediately if you encounter another user's data and report it.

03

No denial-of-service, automated scanning at scale, or social engineering of staff or users.

04

Report each vulnerability once, with clear reproduction steps and evidence. Duplicates are closed against the earliest valid report.

05

Keep findings confidential until Northwind confirms a fix and agrees to disclosure. Good-faith research is authorized and will not be pursued legally.

Recent activity

CriticalAuth bypass on API token refreshResolved · $8,000
HighStored XSS in dashboard commentsResolved · $3,000
MediumIDOR on invoice export endpointAccepted
LowReflected XSS on search parameterResolved · $150

Found something on Northwind Cloud?

Submit a structured report with steps and evidence. Managed triage reviews it, and a valid finding is rewarded by severity.

Submit a reportBack to programs