Vulnerability disclosure program

Found something? Tell us.

We would rather hear it from you than read about it somewhere else. Safe harbor for good-faith research, rewards published by severity rather than hinted at, and a reply from an actual person within five business days.

Safe harbor · Reply in 5 business days · No account needed to file

Step one of two

Report a vulnerability.

Four fields, about twenty seconds. That is a complete report as far as eligibility goes. Reproduction steps come next, and they are optional.

Any address. You do not need your real name to file.

Prefer email? security@revops.ai. Same policy, same rewards.

Will reporting this get me in trouble?

No. If you follow this policy, we consider your research authorized. We will not pursue legal action against you, we will not ask anyone else to, and we will say so in writing to any third party who asks. If a well-meaning mistake takes you slightly out of bounds, tell us what happened. We would rather work it out with you than escalate it.

In return: stay inside the scope below, use test accounts, do not go looking through data that is not yours, and keep what you find between us. This is a private program, so nothing gets published, by you or by us.

What you get

Every reward here is guaranteed.

Confirm a finding at a given severity and you get what is listed, every time. Rewards are months on a RevOps.ai plan, applied to your account with the monthly credits that plan includes. We assign the severity, we explain how we got there, and you are welcome to argue with us about it.

RevOps.ai vulnerability rewards by severity
SeverityReward
CriticalRemote code execution, data reachable across tenants, full account takeover.12 months of Agency.
HighAuthentication bypass, reading another account’s data, manipulating billing or credit balances.12 months of Team.
MediumStored cross-site scripting, server-side request forgery, information disclosure with a real consequence.3 months of Growth.
LowReflected cross-site scripting with limited reach, logic flaws with bounded impact.2 months of Growth.
InformationalHardening suggestions with no demonstrated exploit path.1 month of Growth.
No negotiation

The reward is settled before you send it.

The table is not an opening position. Confirm a finding at a severity and you get exactly what it says, every time, however inconvenient that finding is for us. Plenty of programs leave the reward open and then talk you down once they know how bad the bug is.

Severity is the only variable, and we show our working when we set it. Send the summary now to start the clock and lock in the reward for your severity. Add reproduction steps whenever you are ready, because nothing is confirmed until we can reproduce it.

Start with the summary
Step one · Summary
Four fields, about twenty seconds. Do this before you write anything up: it timestamps you as first reporter and locks in the reward for your severity.
Step two · Reproduction
Optional, but nothing is confirmed until we can reproduce it. This is what proves the root cause was yours, and the fastest route to your reward.
Triage
We reproduce it, assign a severity, and tell you how we got there. You can argue with us about it.
Reward
The plan months listed for your severity, applied to your account. Guaranteed, and never negotiated down.
Scope

What counts, and what does not.

The out-of-scope list is not us being difficult. These are the reports that arrive without a working exploit behind them, and each one costs a day to rule out.

Areas in and out of scope for the RevOps.ai disclosure program
In scopeapp.revops.ai and everything inside the application
In scopeThe RevOps.ai API
In scopeAuthentication, billing, and credit accounting
In scopeIntegrations and webhooks we publish
In scopeAgent behavior, where you can show a concrete consequence
Limitedrevops.ai, this marketing site
Out of scopeMissing SPF, DKIM, or DMARC records
Out of scopeMissing security headers with no demonstrated exploit
Out of scopeClickjacking on pages with no state-changing action
Out of scopeSelf-XSS, or anything needing a pasted console payload
Out of scopeOutdated library versions with no working exploit path
Out of scopeRaw scanner output submitted without a proof of concept
Out of scopeRate limiting on unauthenticated, non-sensitive endpoints
Out of scopeDenial of service, load testing, resource exhaustion
Out of scopeSocial engineering, physical attacks, compromised devices
Out of scopeVulnerabilities in third-party services we do not control

If you can demonstrate real impact from something marked out of scope, send it anyway. A working exploit beats a category list. Our Acceptable Use Policy and Terms of Service still apply, except where they conflict with the safe harbor above. There, the safe harbor wins.

What happens next

You will not be left wondering.

These are timelines we can actually hold to, which is why they are not measured in hours. A missed promise is worse than a modest one.

5 business days
A human acknowledges your report and confirms your reference.
10 business days
We tell you whether we reproduced it, the severity we assigned, and why.
20 business days
Your reward is confirmed and we arrange the plan months with you.
Through the fix
We keep you posted until the fix ships. What you found stays between us.
The fine print

The rest of the rules.

  • The first person to report a root cause is the one we reward. Duplicates get a genuine thank you and nothing else.
  • One reward per root cause, even where the same bug surfaces in several places.
  • Use test accounts. Do not access, change, or keep data that is not yours, and stop as soon as you have proved the point.
  • No automated scanning at volume against production, and nothing that degrades the service for anyone else.
  • This is a private program. Do not publish it, present it, or otherwise make it public, at any point, including after the fix ships. Reporting a finding to us is not a license to release it later.
  • We do not name researchers publicly and we do not run a hall of fame. Your report and your identity stay between us.
  • Current and former employees, contractors, and their immediate family are not eligible.
  • Nothing in the reward table is discretionary: confirm a finding at a severity and you get the plan months listed against it. Rewards are subject to our Acceptable Use Policy, we cannot reward anyone in a country under applicable sanctions, and any tax is yours to handle.
FAQ

The questions researchers ask.

Will you take legal action if I report a bug?

No. If you follow this policy we consider your research authorized, we will not pursue legal action against you, we will not ask anyone else to, and we will say so in writing to any third party who asks. If a well-meaning mistake takes you slightly out of bounds, tell us what happened and we will work it out with you rather than escalate it.

What exactly do I get?

Months on a RevOps.ai plan at the tier listed for your severity, applied to your account, including the monthly credits that plan comes with. A Critical is a year of Agency, our largest self-serve plan, which is 20,000 credits a month for twelve months. Nothing sits on top and nothing is held back: the table is the whole reward, and we honor it at whatever severity we confirm.

Do I have to write the full report before I get anything?

No, and that is the point of splitting the form. Step one is four fields and takes about twenty seconds. That alone puts you in the queue, timestamps you as first reporter, and locks in the guaranteed reward for whatever severity we assign. Reproduction steps are step two and they are optional. If you want to send them later, note your reference and email it to security@revops.ai, and if you lose the reference, email us from the address you filed with and we will find your report. Do not sit on them, though. Nothing is confirmed until we reproduce the issue, and duplicates are settled by root cause, which only becomes visible in a report detailed enough to run.

What if I disagree with the severity you assign?

Say so, and show us why. Severity is the only thing that decides your reward, so we walk you through how we got to ours rather than hand you a label and leave it there. If your reproduction demonstrates impact we missed, we move it up and you get the higher reward. We would rather argue it out with you at triage than have you walk away feeling shortchanged.

Can I publish what I found?

No. This is a private program, and confidentiality is the trade for the safe harbor and a reward that is fixed before you send anything. What you find stays between us, before the fix and after it. It runs both ways: we do not name researchers publicly either. If you need something for a job application, ask and we will confirm your finding to you in writing, privately.

Do you need my real name?

Not to file a report. Any email address works, and nothing you send us is published anywhere. We do need a RevOps.ai account to apply the plan months to, yours or one we set up for you, but that conversation happens after triage, not before you tell us about the bug.

What if someone already reported it?

The first report of a root cause is the one we reward, and we will tell you honestly if yours was a duplicate, including roughly when the original landed. One reward per root cause, even where the same underlying bug shows up in several places.

Is the marketing site in scope?

Only partly. revops.ai is a mostly static marketing site, so header, cookie, and configuration findings on it are out of scope. Anything that touches a form handler, a redirect, or user data on this domain is in scope, and so is anything that gives you a foothold into the application. If you can demonstrate real impact, send it regardless of what the table says.

Four fields locks in your reward.

You do not need a write-up, a proof of concept, or your real name to start. Send the summary and we will take it from there.

Report a vulnerability

Or email security@revops.ai · Policy at /.well-known/security.txt

Report a Vulnerability - RevOps.ai