Program details updated September 2026

Report a security vulnerability

Mellowtel's formal bug bounty scope is still being finalized, but private security reports are open now and eligible findings may be rewarded.

If you believe you have found a security vulnerability we encourage you to let us know right away in private at info@mellowtel.com or reach out to us on Discord. We will pay you for helping us make the platform safer.

The program currently focuses on the mellowtel-js library. We are defining the full scope and response targets and will publish them here when they are ready.

Bug bounties will go from $25 to $15,000.

Formal program scope is in progress. Security reports are accepted now.