Responsible disclosure & bug bounty policy
We want to hear about any vulnerability you find in Chicago Proxies. Here you will find what is in scope, what we pay for, what we don't pay for and how to report, so neither side gets surprised.

We want to hear about any vulnerability you find in Chicago Proxies. Here you will find what is in scope, what we pay for, what we don't pay for and how to report, so neither side gets surprised.
chicagoproxies.comWe reward demonstrated impact on our systems or our customers. Amounts are in USD.
We acknowledge and fix these if warranted, but don't pay. You can check the full list below before you write the report.
At most, we accept these as Low or Informational. We read them and fix whatever is worth fixing, but they earn no bounty, and labeling the report Critical or High does not change that.
Email [email protected] with the subject Security report. Give us the affected URL, the exact steps to reproduce, which account you used and a proof of concept. You will hear back within 5 business days, with a severity decision within 10 business days.
Machine-readable contact details are at /.well-known/security.txt.
Send a reportPolicy last updated 2026-10-10.