Vulnerability disclosure policy
Found a security problem? Here is where to send it and how to test without trouble from us.
AESHA Technology Services Limited · Last revised 7 October 2026 · All legal documents
1. Where to report
Email [email protected] with "Security" in the subject. Please include:
- what is affected — the URL, the endpoint, the plugin or SDK and its version;
- the steps to reproduce it, and what an attacker gains;
- any request, response or proof of concept, with real people's data removed.
A person reads every report and replies. If you do not hear back within a week, send it again — mail does get lost. The same details are published, machine-readable, at https://offerwall.gg/.well-known/security.txt.
2. In scope
- offerwall.gg — the website, the dashboards, the offerwall, the API, the postback and payment endpoints.
- The plugins and SDKs downloaded from /developers/plugins.
Out of scope: the advertising networks, payment processors and other services listed on the subprocessors page — report those to the company concerned — and the websites advertisers send users to.
3. Rules for testing
- Use your own accounts. Sign up as a publisher or advertiser; it is free and immediate.
- Do not access, change or delete anybody else's data. If you reach some by accident, stop, do not keep a copy, and tell us what you saw.
- Do not move real money. If you find a way to credit a balance, show it with the smallest possible amount and tell us, so it can be reversed.
- No denial of service, no load testing, and no automated scanning heavy enough to trip our rate limits.
- No phishing, social engineering or physical attacks on our staff, publishers, advertisers or their users.
- Do not use a finding beyond what is needed to show it exists.
- Give us a reasonable time to fix it before you publish anything, and agree the date with us.
4. Our side
If you follow these rules in good faith, we will not take legal action against you for your research, and we will not ask anybody else to. If somebody else does over research that followed this policy, we will say so publicly.
We tell you what we found, and when it is fixed. If you want, we will thank you by name on this page once the fix is live.
We do not run a paid bug bounty, and nothing on this page promises a payment.
5. Not usually a vulnerability
These are known and deliberate, so please do not report them on their own:
- An offerwall placement's public key appearing in a page or an app — that is what the public key is for. A secret key that leaks is a real report.
- The offerwall being embeddable on a publisher's site — it is built to be framed, by the sites its publisher allows.
- Missing headers or cookie flags with no way to exploit them, and reports from a scanner with no proof behind them.