We would rather hear it from you than read about it somewhere else. Safe harbor for good-faith research, rewards published by severity rather than hinted at, and a reply from an actual person within five business days.
Safe harbor · Reply in 5 business days · No account needed to file
No. If you follow this policy, we consider your research authorized. We will not pursue legal action against you, we will not ask anyone else to, and we will say so in writing to any third party who asks. If a well-meaning mistake takes you slightly out of bounds, tell us what happened. We would rather work it out with you than escalate it.
In return: stay inside the scope below, use test accounts, do not go looking through data that is not yours, and keep what you find between us. This is a private program, so nothing gets published, by you or by us.
Confirm a finding at a given severity and you get what is listed, every time. Rewards are months on a RevOps.ai plan, applied to your account with the monthly credits that plan includes. We assign the severity, we explain how we got there, and you are welcome to argue with us about it.
| Severity | What that looks like | Reward |
|---|---|---|
| CriticalRemote code execution, data reachable across tenants, full account takeover. | Remote code execution, data reachable across tenants, full account takeover. | 12 months of Agency. |
| HighAuthentication bypass, reading another account’s data, manipulating billing or credit balances. | Authentication bypass, reading another account’s data, manipulating billing or credit balances. | 12 months of Team. |
| MediumStored cross-site scripting, server-side request forgery, information disclosure with a real consequence. | Stored cross-site scripting, server-side request forgery, information disclosure with a real consequence. | 3 months of Growth. |
| LowReflected cross-site scripting with limited reach, logic flaws with bounded impact. | Reflected cross-site scripting with limited reach, logic flaws with bounded impact. | 2 months of Growth. |
| InformationalHardening suggestions with no demonstrated exploit path. | Hardening suggestions with no demonstrated exploit path. | 1 month of Growth. |
The table is not an opening position. Confirm a finding at a severity and you get exactly what it says, every time, however inconvenient that finding is for us. Plenty of programs leave the reward open and then talk you down once they know how bad the bug is.
Severity is the only variable, and we show our working when we set it. Send the summary now to start the clock and lock in the reward for your severity. Add reproduction steps whenever you are ready, because nothing is confirmed until we can reproduce it.
Start with the summaryThe out-of-scope list is not us being difficult. These are the reports that arrive without a working exploit behind them, and each one costs a day to rule out.
| In scope | app.revops.ai and everything inside the application |
|---|---|
| In scope | The RevOps.ai API |
| In scope | Authentication, billing, and credit accounting |
| In scope | Integrations and webhooks we publish |
| In scope | Agent behavior, where you can show a concrete consequence |
| Limited | revops.ai, this marketing site |
| Out of scope | Missing SPF, DKIM, or DMARC records |
| Out of scope | Missing security headers with no demonstrated exploit |
| Out of scope | Clickjacking on pages with no state-changing action |
| Out of scope | Self-XSS, or anything needing a pasted console payload |
| Out of scope | Outdated library versions with no working exploit path |
| Out of scope | Raw scanner output submitted without a proof of concept |
| Out of scope | Rate limiting on unauthenticated, non-sensitive endpoints |
| Out of scope | Denial of service, load testing, resource exhaustion |
| Out of scope | Social engineering, physical attacks, compromised devices |
| Out of scope | Vulnerabilities in third-party services we do not control |
If you can demonstrate real impact from something marked out of scope, send it anyway. A working exploit beats a category list. Our Acceptable Use Policy and Terms of Service still apply, except where they conflict with the safe harbor above. There, the safe harbor wins.
These are timelines we can actually hold to, which is why they are not measured in hours. A missed promise is worse than a modest one.
No. If you follow this policy we consider your research authorized, we will not pursue legal action against you, we will not ask anyone else to, and we will say so in writing to any third party who asks. If a well-meaning mistake takes you slightly out of bounds, tell us what happened and we will work it out with you rather than escalate it.
Months on a RevOps.ai plan at the tier listed for your severity, applied to your account, including the monthly credits that plan comes with. A Critical is a year of Agency, our largest self-serve plan, which is 20,000 credits a month for twelve months. Nothing sits on top and nothing is held back: the table is the whole reward, and we honor it at whatever severity we confirm.
No, and that is the point of splitting the form. Step one is four fields and takes about twenty seconds. That alone puts you in the queue, timestamps you as first reporter, and locks in the guaranteed reward for whatever severity we assign. Reproduction steps are step two and they are optional. If you want to send them later, note your reference and email it to security@revops.ai, and if you lose the reference, email us from the address you filed with and we will find your report. Do not sit on them, though. Nothing is confirmed until we reproduce the issue, and duplicates are settled by root cause, which only becomes visible in a report detailed enough to run.
Say so, and show us why. Severity is the only thing that decides your reward, so we walk you through how we got to ours rather than hand you a label and leave it there. If your reproduction demonstrates impact we missed, we move it up and you get the higher reward. We would rather argue it out with you at triage than have you walk away feeling shortchanged.
No. This is a private program, and confidentiality is the trade for the safe harbor and a reward that is fixed before you send anything. What you find stays between us, before the fix and after it. It runs both ways: we do not name researchers publicly either. If you need something for a job application, ask and we will confirm your finding to you in writing, privately.
Not to file a report. Any email address works, and nothing you send us is published anywhere. We do need a RevOps.ai account to apply the plan months to, yours or one we set up for you, but that conversation happens after triage, not before you tell us about the bug.
The first report of a root cause is the one we reward, and we will tell you honestly if yours was a duplicate, including roughly when the original landed. One reward per root cause, even where the same underlying bug shows up in several places.
Only partly. revops.ai is a mostly static marketing site, so header, cookie, and configuration findings on it are out of scope. Anything that touches a form handler, a redirect, or user data on this domain is in scope, and so is anything that gives you a foothold into the application. If you can demonstrate real impact, send it regardless of what the table says.
You do not need a write-up, a proof of concept, or your real name to start. Send the summary and we will take it from there.
Report a vulnerabilityOr email security@revops.ai · Policy at /.well-known/security.txt