WATER DAMAGE EMERGENCY? CALL 619-320-2700 | TEXT US
619-320-2700

Cal Coast Bug Bounty

You find a real security issue in our infrastructure. We pay you. We credit you. We don't sue you. Help us protect the homeowners and insurance carriers who trust us.

Why We Run This

Restoration companies handle sensitive customer data: home addresses, insurance policies, signatures on legal documents, photos of homes during vulnerable moments. We believe every customer deserves an honest partner who actively hardens their infrastructure. A bug bounty program means we engage the security community instead of hoping nobody notices.

Reward Tiers

Critical
$500
RCE, full account takeover, data breach with PII exposure
High
$250
SSRF, stored XSS with sensitive data, auth bypass
Medium
$100
Reflected XSS, CSRF on sensitive actions, subdomain takeover
Low
$25
Information disclosure, security header misconfig with impact

Rewards paid via Stripe or PayPal within 30 days of confirmed and patched issue. Hall of Fame credit available for all valid reports.

Scope

In scope:

Out of scope:

Submission Process

Email josiah@gowithcalcoast.com with subject "SECURITY REPORT". Include:

Our Response Timeline

Safe Harbor

Research conducted in good faith consistent with this policy is authorized. We will not pursue civil action or report security researchers to law enforcement provided you:

Hall of Fame

Researchers who submit valid reports are credited publicly at /.well-known/hall-of-fame.txt (with your permission). LinkedIn endorsements and professional reference letters available on request.

Why We Pay Small Amounts

We're a regional restoration company, not a tech giant. We pay what we can sustainably. Most reporters tell us they appreciate that a local San Diego business engages the security community at all. We hope to grow these rewards over time.

Questions

Reach out via josiah@gowithcalcoast.com or call 619-320-2700.