# What is stored, and what is never sent

**Updated:** 2026-10-04

## Reports are treated as hostile input

A vulnerability report is the one thing you receive that is deliberately an attack. Everything here follows from that.

- Report text is sanitized when it arrives, so a report cannot carry working script into your workspace.
- Attachments always download and never render, and each download is written to the audit log.
- No URL in a report is ever fetched by TotalCtrl.
- The report body is never copied into an issue, a Jira ticket, a webhook payload, or anything the AI assistant returns.

## Reporters are not users

Somebody who reports a bug is identified by an email address and a link. They hold no seat, have no password, and can reach nothing but their own reports.
## The audit trail

Every state change is recorded — who, when, from what to what, and why — and that record is never edited or deleted. It is the evidence of how a report was handled, and the disagreements a program has are all about that history.
## No payouts here

Bug Bounty does not move money. Publish your reward ranges, decide what a report is worth, and pay it through your own finance process.


---
[← Back to TotalCtrl Help Center](https://help.totalctrl.app/en-US/)