Skip to main content

Bug bounty

How to responsibly disclose a security issue and what we pay.

Last updated: 2026-04-07

Scope

In scope:

  • Wellex iOS and Android apps.
  • The bracelet firmware.
  • app.wellex.io and api.wellex.io.

Out of scope:

  • Marketing pages on wellex.io.
  • Phishing, social engineering or DoS.
  • Issues that require physical access to the bracelet.

Rewards

SeverityReward
Critical$5 000 – $15 000
High$1 500 – $5 000
Medium$300 – $1 500
Low$50 – $300

How to report

Send a detailed write-up to [email protected]. PGP key is published at wellex.io/.well-known/security.txt.

Hall of fame

Researchers who report a valid finding are credited (with permission) on our security page. We also send a Wellex bracelet as a thank you for any High or Critical finding, regardless of the cash reward.