Bug Bounty Program
Last Update: September 15, 2026
Security Vulnerability Disclosure & Bounty Disclaimer
The Manhattan Institute encourages responsible reporting of security vulnerabilities affecting our public-facing systems. To submit a vulnerability report and be considered for a bug bounty award, please review the scope, testing rules, and submission requirements below.
Scope & Testing Rules
Public websites, applications, APIs, and official subdomains operated by Manhattan Institute, including manhattan.institute and city-journal.org, are in scope unless otherwise stated. Internal networks, employee devices, physical locations, social engineering, phishing, credential attacks, denial-of-service activity, and third-party systems not owned or operated by MI are out of scope unless MI expressly authorizes testing in writing.
A vulnerability in a third-party platform may be considered only when the issue is caused by an MI-controlled configuration or integration, or when it directly compromises an MI-controlled asset. Pure vendor-platform vulnerabilities may be referred to the vendor and are not automatically eligible for an MI bounty.
Prohibited activities include:
- Denial-of-service, load testing, or automated volumetric scanning that could disrupt service.
- Phishing, social engineering, pretexting, credential stuffing, password spraying, or attacks against MI personnel.
- Testing physical security, employee devices, internal networks, or third-party systems that are not expressly in scope.
- Accessing, downloading, retaining, modifying, or deleting sensitive data beyond the minimum necessary to demonstrate the vulnerability.
- Establishing persistence, deploying malware, changing credentials, or taking actions that could impair systems or users.
- Public disclosure of vulnerability details before MI has completed remediation or provided written authorization for disclosure.
Severity Classification
Manhattan Institute evaluates reported vulnerabilities based on real-world impact, exploitability, affected assets, sensitivity of data, required user interaction, and breadth of compromise. A vulnerability does not need to be classified as Critical to qualify for bounty consideration, and technical vulnerability type or CVSS score alone does not determine severity.
| Severity | MI Definition |
| Critical | A vulnerability that could result in broad compromise of MI systems, privileged access, exposure of highly sensitive donor, financial, employee, or organizational data, or compromise of payment or donation infrastructure. |
| High | A vulnerability that could result in significant unauthorized access, account takeover, sensitive data exposure, execution of attacker-controlled code, or abuse of a trusted MI-controlled system or domain. |
| Medium | A reproducible vulnerability with meaningful but limited security impact, such as certain session-management weaknesses, cross-site scripting, authorization flaws, or redirect vulnerabilities with a credible abuse scenario. |
| Low | A vulnerability with limited security impact, significant exploitation prerequisites, or primarily defense-in-depth value. |
| Informational | A best-practice recommendation, theoretical issue, scanner-only result, or finding with no demonstrated security impact. Informational findings generally do not qualify for a bounty. |
Bounty Eligibility & Evaluation
Critical, High, Medium, and Low findings may be considered for a bounty. Informational findings generally are not eligible. All reports are reviewed on a case-by-case basis. Bounty eligibility and award amounts are determined by Manhattan Institute at its discretion based on severity, demonstrated business impact, exploitability, affected assets, novelty, report quality, and whether the issue was previously known or already under remediation.
Manhattan Institute does not publish or guarantee fixed bounty amounts. A valid report does not guarantee a bounty. Bounties will not be paid to any individual who is on any prohibited person and organization list published by any unit of government of the United States, or to an individual whom MI reasonably suspects may be associated with a prohibited person or prohibited organization.
Submission Guidelines
Send reports to bounty@manhattan.institute and include:
- A clear description of the vulnerability and the affected URL, application, endpoint, or system.
- Step-by-step reproduction instructions or a proof-of-concept sufficient for MI to independently validate the issue.
- Supporting evidence where appropriate, such as screenshots, request/response data, logs, or non-destructive scripts.
- A concise explanation of the realistic security impact and likely abuse scenario.
- A contact name or handle and a reliable email address for follow-up.
Do not submit sensitive data collected from MI systems. If you encounter sensitive information, stop testing and report the issue immediately with the minimum evidence necessary to demonstrate the vulnerability.
If a bounty is approved based on the content and findings, MI Finance or Legal may request a legal name, tax documentation, identity verification, or other information required for payment, sanctions screening, or legal compliance. This information is not required for initial technical triage unless specifically requested. If we conclude that we are unable to pay a bounty because you are not eligible for one—for instance, because we believe you may be on a prohibited persons list or associated with a prohibited organization—then we will explain why and give you an opportunity to respond before we make a final decision on eligibility.
Legal Safe Harbor
Manhattan Institute will not initiate legal action against a researcher for good-faith security research that complies with these guidelines, is limited to MI-controlled in-scope systems, avoids unnecessary access to data, and is promptly reported to MI.
Safe harbor does not apply to conduct outside these guidelines, including extortion, threats, fraud, privacy violations, service disruption, unauthorized access to third-party systems, or retention or disclosure of sensitive information. These guidelines do not waive the rights of third parties or authorize testing of systems they own or operate.
Zero Tolerance for Threats, Extortion, or Fraud
Any attempt to coerce, threaten, harass, extort, or defraud Manhattan Institute personnel, including conditioning nondisclosure on payment or threatening public release to obtain a bounty, will result in immediate removal from the program and permanent ineligibility for current or future bounty payments. MI may refer unlawful conduct to appropriate authorities.
Thank you for helping us keep the Manhattan Institute community and our public systems secure.