Confidentiality undertaking
Last updated: 4 September 2026
This text is a draft. Have your legal counsel review it before you publish.
Why this document exists
The software you test is usually a build nobody outside the company has seen. Its screens, its features, when it ships and the faults inside it are that company's trade secret. You accept this document before you take a job.
Who it is between
The undertaking is between the person doing the testing and the company giving the work. BountyShift is not a party to it; it enforces it. An account that breaks the undertaking is acted on.
What counts as confidential
The build and installer given to you, screenshots and recordings you take, the test steps and scenarios, the company's name and product names, release dates and pricing, the faults you find, and any data you see while working.
What is not confidential
Anything already public before you learned it, anything that becomes public later through no fault of yours, and anything the company has given you written permission to share. Showing that something falls in this group is on you.
What you will not do
You will not share, copy or redistribute the build. You will not take screenshots or recordings outside the platform. You will not describe it on social media, in a forum, on a livestream or in a group chat. Telling a friend whose product you are testing is covered by this too.
The faults you find are confidential as well
When you find a fault or a security weakness you report it through the platform and nowhere else. Passing it to a third party, taking it to another bounty programme or making it public breaks this undertaking.
What you may use the build for
Only for the job you were given. Using it for your own work, reverse engineering it, trying to reach its source, or getting around its licence protection all sit outside that job.
Devices and storage
You keep test files on your own device, where nobody else can reach them. You do not work on a shared or public computer. You do not put the files in a shared folder or let them sync to a cloud backup.
Deleting when the job closes
Once a job closes you delete the build and every file belonging to it from your device. The record of your work stays on the platform; no copy stays with you.
How long it lasts
The obligation starts the moment you take the job and does not end when the job does. It runs until the build is public, and in any case for three years after the job closes.
When the law requires disclosure
If a court or a competent authority requires disclosure, you tell us as soon as you can and disclose only as much as was asked for.
What a breach costs
A confirmed breach cancels the job, the fee for that job is not paid, and the account is suspended. The company keeps its right to pursue direct losses through the courts.
When you are not sure
If you are not sure whether a file or an image can be shared, do not share it — ask first. This document works on a question asked, not on a guess.
Accepting
Taking a job from the queue means you have accepted this document. The moment you accepted is written into your account's record.