If cracking an internal service is possible, a bug exploiting it should be within scope of any bounty program.
If cracking an internal service is possible, a bug exploiting it should be within scope of any bounty program.