Bug bounty
How to responsibly disclose a security issue and what we pay.
Last updated: 2026-04-07
Scope
In scope:
- Wellex iOS and Android apps.
- The bracelet firmware.
- app.wellex.io and api.wellex.io.
Out of scope:
- Marketing pages on wellex.io.
- Phishing, social engineering or DoS.
- Issues that require physical access to the bracelet.
Rewards
| Severity | Reward |
|---|---|
| Critical | $5 000 – $15 000 |
| High | $1 500 – $5 000 |
| Medium | $300 – $1 500 |
| Low | $50 – $300 |
How to report
Send a detailed write-up to [email protected]. PGP key is published at wellex.io/.well-known/security.txt.
Hall of fame
Researchers who report a valid finding are credited (with permission) on our security page. We also send a Wellex bracelet as a thank you for any High or Critical finding, regardless of the cash reward.