Skip to main content
circus
    • Creator App
      The dedicated app for running a community
    • Creator Fund
      How we'll pay creators on Circus
    • Creator Guide
      Step-by-step guide to getting started
    • Advertise
      Reach engaged Circus communities
    • Advertiser Guide
      Ad formats, specs, and how placements work
    • Safety hub
      Our approach to trust and safety
    • Community Guidelines
      Rules for all communities
    • Content Guidelines
      What's allowed on Circus
    • Moderation
      How moderation works
    • Parents & Guardians
      A guide for families
    • Report Form
      Flag harmful content or accounts
    • Support Services
      Crisis and mental health support lines
    • Law Enforcement
      Legal data requests
    • What is Circus?
      How communities, creators, and the platform fit together
    • All guides
      Guides and resources
    • Creator Guide
      Get started as a creator
    • Posting Guide
      Post types, formats, and what works
    • Advertiser Guide
      Ad formats, specs, and brand-safe advertising
    • Manifesto
      Our principles and what we stand for
    • Policies
      Every Circus policy in one place
    • Contact
      Get in touch with the right team
    • Engineering Blog
      Engineering decisions and technical writing from the team
    • Support
      Help with your account, app, and questions
Download on the App Store Get it on Google Play
Creator AppAdvertisersSafetyGuidesSupport
Company
ManifestoPoliciesContact
Download Circus

Security

Last updated 21 May 2026

Responsible disclosure policy and bug bounty program.

Our Commitment

Circus takes the security of our platform and the privacy of our users seriously. We run regular internal security reviews, commission third-party penetration testing before significant releases, and encrypt user data at rest and in transit. We welcome reports from security researchers who identify vulnerabilities in good faith and give us the opportunity to fix them before public disclosure.

Scope

In Scope

  • Authentication and account security
  • API endpoints and data access controls
  • iOS and Android mobile applications
  • User data privacy and potential leakage
  • Payment processing flows
  • Content delivery and media infrastructure
  • Admin tooling and internal dashboards
  • CDN and infrastructure configuration

Out of Scope

  • Social engineering of Circus staff
  • Physical security attacks
  • Denial of service attacks
  • Issues in third-party services we don’t control
  • Automated scanning without prior written permission
  • Vulnerabilities in outdated browsers or OS versions

How to Report

Email security@circus.app with:

  • A clear description of the vulnerability and its location
  • Step-by-step reproduction instructions
  • Your assessment of the potential impact
  • Any proof-of-concept code (non-destructive only — do not exfiltrate user data)

PGP encryption is available on request. We will acknowledge receipt within 48 hours and provide a response timeline based on severity.

Response Timeline

  • Critical — Acknowledgement within 24h · Fix target within 7 days
  • High — Acknowledgement within 48h · Fix target within 14 days
  • Medium — Acknowledgement within 72h · Fix target within 30 days
  • Low — Acknowledgement within 7 days · Fix target within 90 days

Bug Bounty Rewards

Pre-launch, we offer recognition in place of cash rewards. Findings are rewarded based on severity:

  • Critical / High — Named on our Hall of Fame, Circus swag package, credit in our security changelog
  • Medium / Low — Named on our Hall of Fame, written acknowledgement

We intend to introduce paid bounties proportional to severity after public launch. Pre-launch findings will be honored at the severity rating agreed at disclosure time.

Hall of Fame

No entries yet — be the first to responsibly disclose a security finding.

Safe Harbour

Circus will not initiate or support legal action against security researchers who act in good faith. Specifically, we commit to this protection where researchers:

  • Make reasonable effort to notify us before any public disclosure
  • Avoid accessing, modifying, or exfiltrating user data beyond what is strictly necessary to demonstrate the vulnerability
  • Do not degrade the availability of our services
  • Allow us a reasonable window to investigate and remediate

This commitment does not extend to activity that causes harm to our users or platform, or that falls outside these principles.

Coordinated Disclosure

We follow a standard 90-day coordinated disclosure window from the date we acknowledge a valid report. We will keep you informed at each stage and credit you in our public disclosure unless you prefer to remain anonymous. If a fix requires more time, we will negotiate an extension with you directly rather than leaving the window open indefinitely.


© 2026 Circus Corporation. All rights reserved. Proprietary and confidential.

Contents

  1. Our Commitment
  2. Scope
  3. How to Report
  4. Response Timeline
  5. Bug Bounty Rewards
  6. Hall of Fame
  7. Safe Harbour
  8. Coordinated Disclosure
circus

The fan app — communities for creators, sports teams, and universities.

Download on the App Store Get it on Google Play
Company
  • Manifesto
  • Contact
  • Brand
  • Changelog
  • Engineering Blog
  • Careers
  • Status
Community
  • Creators
  • Advertisers
  • Guides
  • Support
  • Account Actions
  • Report a Bug
Safety
  • Safety Hub
  • Moderation
  • Parents & Guardians
  • Report Form
  • Community Guidelines
  • Content Guidelines
  • Age Verification
  • Prohibited Communities
  • Law Enforcement
  • Support Services
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Practices
  • Copyright Policy
  • Accessibility
  • Licenses
  • Security
  • Bug Bounty
  • Data Requests
  • Online Safety Act
  • Digital Services Act
  • COPPA
  • Advertising Policy
  • AI Policy
  • Anti-Spam Policy
  • Refund Policy
  • Data Processing Agreement

© 2026 Circus Corporation. All rights reserved.

Delaware, United States