Level one — highest priority
Security bug
Issues that can put Cartino users or infrastructure at risk, such as unauthorized access, information exposure, or privacy violations.
Reward value: Based on the severity and impact of the bug
Every helpful report is a step toward a better, safer Cartino. Tell us about the issue
you found and receive a reward based on the value and impact of your report.
Reward amounts are not fixed in advance. After your report is reviewed and approved, the Cartino team determines the final reward.
Level one — highest priority
Issues that can put Cartino users or infrastructure at risk, such as unauthorized access, information exposure, or privacy violations.
Reward value: Based on the severity and impact of the bug
Level two — high priority
Issues involving broken capabilities, failed processes, incorrect results, or disruptions to functional workflows.
Reward value: Higher than rewards for visual bugs
Level three — medium priority
Visual issues, responsive layout problems, alignment errors, and inconsistent rendering across different browsers.
Reward value: Proportional to the value of the bug
Click the “Report a bug” button and follow the submission steps. To submit a report and receive your reward, you first need to create an account or sign in.
After your first report is submitted, a “Track bug reports” option becomes available in your dashboard, where you can review the status of every report you have submitted.
To review a report, we need to be able to observe and investigate the issue. Clear details, the page link, and a screenshot or video can significantly speed up the review and approval process.
If someone else has already reported the same issue or the Cartino team has already identified it, your submission will be marked as a duplicate and will not be eligible for a reward.
Reward amounts are not fixed in advance. The Cartino team determines the final reward based on the severity, impact, and quality of the report.
Reports with complete details, clear reproduction steps, and sufficient evidence are more valuable than vague reports.
Reports submitted with malicious intent or for the deliberate exploitation of a vulnerability are not eligible for any reward.
Testing that intentionally damages Cartino systems, data, or other users’ accounts is strictly prohibited.
Security vulnerabilities must be reported privately to Cartino and must never be publicly disclosed before they are resolved. Otherwise, the report will not be eligible for a reward and may lead to legal action. Once the bug is resolved, you may reference it in your résumé or work history with the Cartino team’s approval.