Win's VPN is used by people for whom a security failure is not an inconvenience.
If you have found a weakness in our software or infrastructure, we want to hear from you, and we
will not take legal action against you for telling us.
Safe harbour
If you make a good-faith effort to follow this policy while researching a vulnerability, we
will consider your research authorised, we will work with you to understand and fix the issue
quickly, and we will not initiate or support legal action against you.
If a third party brings legal action against you for research that complied with this policy,
we will make it known that your activity was authorised.
Act in good faith and stay in scope, and this protection applies. It does not
cover accessing other people's data, degrading the service for real users, or extortion.
How to report
Use the form below. It routes straight to our security team. We do not publish the address
directly, so that the inbox stays usable for real reports.
Please include:
What the issue is and why it matters — the impact, not just the observation.
Clear reproduction steps or a short proof of concept.
Affected component and version — app build number, endpoint, or server role.
How you would like to be credited, or if you would prefer to remain anonymous.
Acknowledgement within 5 business days. We are a small nonprofit, not a
24/7 security team, and we would rather commit to something we can actually meet.
An assessment and our intended action within 15 business days.
Progress updates until the issue is resolved or we explain why we are not
acting on it.
Public credit when a fix ships, if you want it.
On rewards — an honest answer
We do not currently pay bounties. Win's VPN Inc. is a nonprofit; our funds go to keeping free
access running for people under censorship. We offer public credit, a written reference if it
helps your career, and free lifetime premium access for a valid report.
We would rather say this plainly than let you spend a weekend expecting a payment that is not
coming. If a paid programme becomes possible, this page will say so.
Scope
In scope
winsvpn.org and its subdomains
The Win's VPN client applications
The Win For All application
Our control-plane API endpoints
Our VPN node infrastructure — subject to the user-safety rules below
Out of scope
Findings from automated scanners without a demonstrated, exploitable impact
Missing security headers, cookie flags, or TLS configuration preferences with no
demonstrated exploit
Self-XSS, clickjacking on pages without sensitive actions, and issues requiring a rooted or
already-compromised device
Rate limiting on endpoints that do not handle credentials
Social engineering of our staff, partners, or users
Physical attacks against our offices or hardware
Denial of service, volumetric testing, or anything that degrades availability
Vulnerabilities in third-party services we use but do not control
Rules that exist because of who our users are
Many of our users are journalists, activists and ordinary people living under censorship,
where being identified as a VPN user carries real physical risk. Testing that would be merely
rude against a normal service can put a person in danger here. So:
Test only against your own account and your own traffic. Never attempt to
access, intercept, or deanonymise another user's connection, traffic, or account.
Never run availability-affecting tests against production. If a node goes
down, someone loses their only route to the outside world.
If you encounter user data, stop immediately. Do not download it, do not
keep it, tell us at once, and delete anything you obtained.
Do not pivot. Access only what is needed to demonstrate the issue, then
stop.
Disclosure
Please give us 90 days to remediate before publishing, and coordinate the
timing with us. If we cannot fix something in that window we will tell you why and agree an
extension with you rather than going quiet. We will not ask you to stay silent indefinitely, and
we will not treat a disclosure deadline as a hostile act.
Recognition
Researchers who report valid issues are credited here and in the release notes for the fix,
unless they ask not to be.