Stratamesh
Bug bounty Managed triageStratamesh Technologies, Inc.
Multi-tenant Kubernetes: one control plane, eleven thousand tenants, one boundary that matters.
- Accepting reports
- $250 – $25,000
- 9 assets in scope
- Launched Mar 2018
- stratamesh.example
Read the policy · first response 1 business day for Critical, 2 for everything else
Response times
- first response
- 4 hours
- triage
- 1 day
- reward
- 8 days
- resolution
- 26 days
Program to date
- Resolved
- 3,182
- Total paid
- $3.05M
- Thanked
- 761
- Average
- $2,914
Rewards by severity
Final amounts depend on demonstrated impact, report quality and asset criticality.
| Severity | CVSS | Reward | Typical findings |
|---|---|---|---|
| Critical | 9.0 – 10.0 | $9,000 – $25,000 | Cross-tenant data access, control-plane remote code execution, cluster-admin escalation from an unprivileged workload, extraction of an image-signing key. |
| High | 7.0 – 8.9 | $3,200 – $8,500 | Authentication bypass on the control-plane API, container escape to the node, IAM role confusion that hands one tenant another tenant's object store. |
| Medium | 4.0 – 6.9 | $750 – $2,800 | Stored scripting in the operator console, request forgery reaching an internal metadata endpoint, role confusion inside a single tenant. |
| Low | 0.1 – 3.9 | $250 – $700 | Stack traces that print internal paths, sessions that survive a password change, a signed URL that outlives its stated lifetime. |
In scope
9 assets listed, 8 eligible for a reward. Anything not on this list is out of scope.
| Asset | Type | Max severity | Reward | Notes |
|---|---|---|---|---|
| *.stratamesh.example | Domain | Critical | Eligible | Tenant subdomains. Trial tenants are free and provision in under a minute; make a second one if you need to show a crossing. |
| https://api.stratamesh.example/v3 | API | Critical | Eligible | Control plane, REST and gRPC gateway, on the v3 schema since the 2021 rewrite. Rate limited to 20 rps per source IP; ask before load testing. |
| https://console.stratamesh.example | URL | Critical | Eligible | Operator console, including the workload shell and the live log stream. Both proxy through the control plane, so trace where the check is missing. |
| registry.stratamesh.example | API | Critical | Eligible | Image registry and signature verification. On the admission path since the 2024 consolidation, which is why it pays at the top band. |
| *.stratamesh-edge.example | Domain | High | Eligible | Regional ingress and routing. Request smuggling and host-routing confusion get read first; the edge fleet runs three proxy versions at any time. |
| strata | Executable | High | Eligible | Signed CLI for Linux, macOS and Windows. Current minor and one behind. Update-channel and plugin-loader findings are welcome. |
| terraform-provider-stratamesh | Source code | Medium | Eligible | Eligible since June 2026. State-file credential leaks and unsafe defaults count; a tested patch adds a flat bonus. |
| ops2.stratamesh.example | URL | Medium | Eligible | Pre-rewrite operations console, kept alive for three EU tenants who have not migrated. Caps at Medium and is switched off in March 2027. |
| billing.stratamesh.example | URL | High | No reward | Invoicing portal running in our billing vendor's environment. In scope to report, not eligible for a reward: we forward and chase, they pay nothing. |
Out of scope
| Asset | Why |
|---|---|
| v1.stratamesh.example | The v1 control-plane API left scope on 30 June 2024 and was switched off that December. What answers there now is a redirect, and nothing behind it is actionable. |
| blog.stratamesh.example | Marketing content in a hosted publishing tool. Separate origin, separate session, no tenant data. |
| status.stratamesh.example | Run by our status vendor under their own disclosure policy. Send it to them and they will honour it. |
| stratamesh.example/careers | Applicant tracking iframe belonging to a recruiting vendor. We cannot authorise testing of their platform. |
| Corporate helpdesk, CRM and HR tooling | Not the product. We want to hear about it at the contact address, but no bounty applies. |
| Workloads and images our customers run on the platform | Customer code. If it is exploitable, the finding belongs to the customer, not to us. |
Findings that will be closed as informative
- Scanner output with no reproduction and no stated impact.
- Header and cookie-flag observations with nothing built on top of them.
- Rate-limit gaps on endpoints that change no state and cost us nothing.
- Kubernetes CVEs reported against versions we patch on a published schedule.
- Subdomain takeover claims where the CNAME resolves to a live service.
- Self-inflicted scripting, clickjacking on anonymous pages, and tabnabbing with no privileged action behind it.
- Anything that presumes a rooted or already-compromised client machine.
- Mail policy opinions: sender records, deliverability, spoofing of addresses we do not sign.
- Findings against ops2 that also reproduce on the current console: report the current one.
Program policy
Program overview
Stratamesh schedules customer workloads across regional Kubernetes fleets and puts one control plane, one console and one CLI in front of them. Eleven thousand four hundred organisations run production traffic on it today. There were fewer than three hundred when this program opened in March 2018, and most of the policy below exists because of something that happened in between.
The control plane is the product, so the control plane is where the money goes. Anything that lets one tenant observe, influence or reach another is the most serious class of finding we accept, and that has been true across three versions of the reward table. The figures beside this policy are the real ones: 3,182 reports resolved, 761 researchers thanked, just over 3.05 million USD paid. Triage came back in-house in November 2025, and every report scored High or above gets an engineer from the owning service on the ticket the same day.
Testing rules and expectations
Create your own tenant at console.stratamesh.example. Trial tenants cost nothing and provision in about forty seconds; if you need two to show a crossing, make two and say in the report which one was the attacker.
- Twenty requests per second per source IP against the API, five against
/v3/auth/*. Ask before anything heavier and we will usually agree a window. Unannounced load is blocked at the edge, and we do not lift a block while a session is running. - Send
X-Stratamesh-Research: <your handle>on every request and suffix test addresses with+bbp. Traffic we cannot attribute is handled as an intrusion until someone proves otherwise, which costs you an evening and costs us a bridge call. - Stop at proof. One object identifier belonging to a tenant that is not yours settles the question. A thousand of them turns a bounty into an incident review with counsel in the room.
- Keep identifiers, not records. Delete anything you pulled within seven days and confirm it in the thread.
- Never: denial of service, resource-exhaustion experiments on shared nodes, social engineering of our staff or our customers, physical attempts, or testing aimed at the cloud providers underneath us.
If your testing breaks something, tell us in the report the same hour. A self-reported accident has never cost anyone a bounty here. The one concealed one ended a participation.
Proving write access
If you find a way to write, do not prove it by causing damage. Prove it with the smallest change that can be attributed to you and undone in the same minute.
- One or two punctuation characters. Delete a full stop, add a comma. Nothing longer, nothing visible, no payload, no changed number or amount.
- Only on a record you created yourself. Never another user's record, never site content, never anything the public can see.
- Revert within sixty seconds, in the same run, without being asked.
- Capture four states: before, after the change, after the revert, and an independent re-read confirming the revert held.
- If it cannot be reverted, do not change it. Report the write primitive and stop. A row count and a column list already prove database access.
Every request must carry headers that let us separate your traffic from a real attack in our logs:
X-Bug-Bounty: stratamesh
X-Research-Account: <the account you submit the report under>
X-Authorisation-Ref: <engagement or report reference>
X-Request-Id: <unique per request>
User-Agent: sentinel-research/<handle> (+<this page>)
scripts/proof_of_write.py performs exactly this sequence, refuses any host
outside the scope above, refuses a diff longer than two characters, always
attempts the revert, and writes a timestamped evidence file. Run it without
--execute first, then attach the evidence to your report.
Safe harbor
Work that stays inside this policy is authorised work, and we will put that in writing for anyone who asks: your employer, your registrar, a hosting provider, a court. We have sent that letter twice since 2019 and neither researcher had to ask twice.
Good faith means you tested the assets listed above, stayed inside tenants you created, took the minimum the proof required, and gave us a chance to ship a fix before anyone else heard about it.
Authorisation ends the moment you pull another tenant's data past the point of proof, sell or trade a finding, use the access for anything other than proving the bug, or attach a price to the report. None of those are research and none of them are covered here.
Reward decisions
CVSS v3.1 picks the band and reachability sets the position inside it. A 9.8 that needs cluster-admin credentials you already hold will pay less than a careful 7.4 that reaches another tenant's object store from an unprivileged pod.
The first reproducible report takes the finding. Since February 2026 the duplicate window runs from the moment the earlier report was triaged rather than from the moment it arrived, because measuring from arrival let an untouched queue item beat a complete write-up. When we close something as a duplicate we name the report it duplicates and the date it was triaged.
Chains pay at the severity of the chain, with up to 25% added for the work of assembling it. A finding against the CLI or the Terraform provider that arrives with a patch we can merge earns a flat 1,500 USD on top.
Disclosure policy
Ninety days, counted from the day we triage a report as valid. Publish when the fix ships or when the window closes, whichever comes first. If we need longer we ask before day 75 with a reason and a date; node-image changes are the usual cause, because they roll region by region behind a maintenance calendar our customers set.
Redact tenant identifiers, internal hostnames, customer names and anything shaped like a key or token. We read drafts within five working days. We have never asked a researcher to soften a technical claim and we do not intend to start.
Report quality
- The asset and endpoint, with the full request including headers.
- Both tenant identifiers and the handle you sent in
X-Stratamesh-Research. - Numbered steps that start from a fresh trial tenant, with nothing skipped as obvious.
- One sentence on what the attacker gains, in terms of tenant data or control-plane privilege.
- The UTC window you tested in, so we can line it up against our own logs.
- Video only where timing is the point. For everything else a curl transcript is faster to read and faster to act on.
Hall of fame
Researchers who have reported valid issues to this program.
| # | Researcher | Country | Reports | Points |
|---|---|---|---|---|
| 1 | etcd_whisper | Netherlands | 88 | 7,412 |
| 2 | cgroup_drift | Germany | 71 | 6,905 |
| 3 | sidecar_sue | United States | 96 | 6,240 |
| 4 | kubelet_kai | Japan | 64 | 5,517 |
| 5 | mira.kowal | Poland | 58 | 4,986 |
| 6 | runc_rabbit | Brazil | 39 | 4,401 |
| 7 | admission_ana | Spain | 52 | 3,970 |
| 8 | tenantsplit | Türkiye | 47 | 3,508 |
| 9 | cni_hopper | Kenya | 26 | 3,022 |
| 10 | sandbx | India | 35 | 2,744 |
| 11 | oci_layercake | Canada | 29 | 2,318 |
| 12 | nodeport_nim | South Africa | 24 | 1,960 |
| 13 | ingress_ivo | Czechia | 18 | 1,612 |
| 14 | yamlrot | Australia | 21 | 1,285 |
| 15 | csi_marta | Portugal | 12 | 974 |
| 16 | pod_drifter | Viet Nam | 9 | 641 |
Program updates
-
Image signing now pays at the Critical band
Registry findings used to cap at High because the registry sat beside the platform rather than in it. It has been on the admission path since the 2024 consolidation, so the band now matches what a forged signature actually buys an attacker.
-
Terraform provider brought into scope
The provider repository is eligible at Medium. A report that arrives with a patch we can merge earns a flat 1,500 USD on top of the band.
-
Duplicate window now runs from triage
We closed a report as a duplicate of a queue item nobody had looked at for nine days, which was our failure and not the reporter's. The window is measured from the moment the earlier report was triaged. Two closures from 2025 were reopened and paid the same week.
-
Triage is back in-house
The firm that ran first-line triage for us since late 2023 finished in October. Same queue and same targets, but the person reading your report now works on the service you are reporting against.
-
Critical ceiling raised to 25,000 USD
Cross-tenant findings had been paying out near the old 20,000 cap for two years, which meant the cap was doing the scoring. It now tops out at 25,000 for reports triaged on or after this date.
-
The v1 API left scope
v1 stopped taking new tenants in 2022 and came out of scope today. It was switched off in December; anything sent against the redirect since then has been closed as not applicable.
-
Advisory SM-2023-07 published with credit
A container escape reported in August was fixed in the June and July node images and disclosed on the 19th. Both reporters are named in the advisory at their request.
-
First response for Critical cut to one business day
Critical reports were waiting behind a shared queue on Mondays. They now page the on-call platform engineer directly, and everything else keeps the two-day target.
-
Reopened on the new control plane
v3 is live in every region and the scope table points at it. The v2 surface stayed eligible until the last tenants finished moving in September.
-
Submissions frozen for the control-plane migration
The rewrite moves tenants region by region between 19 April and 4 June and the surface changes under you while it runs. Nothing new is accepted in that window; reports already in triage carry on as normal.
-
Reward table raised for the first time
Critical moved from 4,000 to 9,000 USD and Medium doubled. The launch table was written for a platform with under three hundred tenants and had stopped being honest about a year earlier.
-
Program opened, invitation only
Twenty-two researchers, four bands topping out at 4,000 USD, and one engineer reading everything. Public submissions opened the following February.