Responsible research and disclosure policy
For you to participate in the program, we require that:
-
You do not interact with an individual account (which includes modifying or accessing data from the account) without the account owner's explicit consent in writing, which you must produce upon request.
-
You make a good faith effort to avoid privacy violations and disruptions to others, including (but not limited to) unauthorized access to or destruction of data, and interruption or degradation of our services. You must not intentionally violate any applicable laws or regulations, including (but not limited to) laws and regulations prohibiting unauthorized access to data.
-
If you inadvertently access another person's data or Meta company data without authorization while investigating an issue, you must promptly cease any activity that might result in further access of user or Meta company data and notify Meta what information was accessed (including a full description of the contents of the information) and then immediately delete the information from your system. Continuing to access another person's data or company data may demonstrate a lack of good faith and disqualify you from any benefit of the Safe Harbor Provisions described below. You must also acknowledge the inadvertent access in any related bug bounty report you may subsequently submit. You may not share the inadvertently accessed information with anyone else.
-
You do not exploit a security issue you discover for any reason other than for testing purposes, and you do not conduct testing outside of your own account, a test account, or another account for which you have the explicit written consent of the account owner to test. (This includes demonstrating additional risk, such as the risk that the security issue could be used to compromise sensitive company data or another user's account.)
-
You give us reasonable time to investigate and mitigate an issue you report before publicly disclosing any information about the report or sharing such information with others.
-
You will receive updates from us regarding the status of your report and our progress toward resolution. Given that every vulnerability is different, the timing, extent, and verbosity of our updates to you will also differ, and will be within Meta’s sole discretion.
-
Not be a resident of, or make your submission from, a country against which the United States has issued export sanctions or other trade restrictions (e.g., Cuba, Iran, North Korea, Syria, the Crimea Region, or any other jurisdiction or area designated by the United States Treasury's Office of Foreign Assets Control).
-
Not be employed by or a contractor/vendor of Meta or its subsidiaries or affiliates, or be an immediate family member of a person employed by Meta or its subsidiaries or affiliates (defined for these purposes as including spouse, domestic partner, parent, legal guardian, legal ward, child, and sibling, and each of their respective spouses, and individuals living in the same household as such individuals).
-
Not be less than 14 years of age - if you are at least 14 years old, but are considered a minor in your place of residence, you must get your parent’s or legal guardian’s permission prior to participating.
Safe harbor provisions
-
We consider these terms to provide you authorization, including under the Computer Fraud and Abuse Act (CFAA) and similar applicable laws and/or regulations, to test the security of the products and systems identified as in-scope below. These terms do not provide you authorization to intentionally access company data or data from another person's account without their express consent, including (but not limited to) personally identifiable information or data relating to an identified or identifiable natural person.
-
If Meta determines in its sole discretion that you have complied in all respects with these Meta Bug Bounty terms in reporting a security issue to Meta, we will not initiate a complaint to law enforcement or pursue a civil action against you, to include civil actions under the CFAA in connection with the research underlying your report and DMCA claims against you for circumventing the technological measures we have used to protect the applications in scope. Meta will also not pursue legal action against you for clear accidental or good faith violations of its policy or these terms.
-
Your use of Meta technologies, including for purposes of this program, remains subject to Meta Terms and Policies and the terms and policies of the Meta services you use. To the extent activities authorized by these Meta Bug Bounty terms are inconsistent with other terms of service for in-scope Meta technologies and programs, we waive those restrictions for the limited purpose of permitting security research under this policy.
-
If legal action is initiated by a third party against you for conduct that Meta determines to have complied with these Meta Bug Bounty terms, Meta will take steps to make it known, either to the public or the court, that your actions were authorized under this program.
Payout Terms
-
Bug Bounty payouts that are not claimed within 6 months from the date of the payout message will be automatically revoked and rendered ineligible for claiming. It is the responsibility of the researcher to claim their payout within this timeframe.