Bug Bounty - Vulnerability discovery

Is there a bug bounty program or some conditions under which users have the freedom to try and detect vulnerabilities in Expensify? Usually it would need the user to register an account with clear "test" username or something, but I am not sure what is the case here - and would not try without permission.