Vulnerability disclosure program

Found something? Tell us.

We would rather hear it from you than read about it somewhere else. Safe harbor for good-faith research, rewards published by severity rather than hinted at, and a reply from an actual person within two business days.

Safe harbor · Reply in 2 business days · No account needed

Step one of two

Report a vulnerability.

Four fields, about twenty seconds. That is a complete report as far as eligibility goes. Reproduction steps come next, and they are optional.

Any address. You do not need your real name to file.

Prefer email? security@revops.ai. Same policy, same rewards.

Will you come after me for this?

No. If you follow this policy, we consider your research authorized. We will not pursue legal action against you, we will not ask anyone else to, and we will say so in writing to any third party who asks. If a well-meaning mistake takes you slightly out of bounds, tell us what happened. We would rather work it out with you than escalate it.

In return: stay inside the scope below, use test accounts, do not go looking through data that is not yours, and give us 90 days before you publish, or until the fix ships if that comes first.

What we pay

Every reward here is guaranteed.

Confirm a finding at a given severity and you get what is listed, every time. We assign the severity, we explain how we got there, and you are welcome to argue with us about it.

RevOps.ai vulnerability rewards by severity
SeverityReward
CriticalRemote code execution, data reachable across tenants, full account takeover.$2,500 in credits, plus 12 months of Agency.Plus cash
HighAuthentication bypass, reading another account’s data, manipulating billing or credit balances.$1,000 in credits, plus 12 months of Team.Plus cash
MediumStored cross-site scripting, server-side request forgery, information disclosure with a real consequence.$250 in credits, plus 3 months of Growth.
LowReflected cross-site scripting with limited reach, logic flaws with bounded impact.$50 in credits.
InformationalHardening suggestions with no demonstrated exploit path.Our thanks, and public credit when the fix ships if you want it.
No headline number

We price it after we can reproduce it.

There is no maximum cash figure on this page because we would be making it up. What a finding is worth depends on what it actually lets someone do, and nobody can judge that from a one-line summary. Plenty of programs paper over that with an eye-catching number they rarely pay.

So we publish the floor instead, and we always honor it. Send the summary now to start the clock and lock in the reward for your severity. Add reproduction steps whenever you are ready, and we will price the rest properly.

Start with the summary
Step one · Summary
Four fields, about twenty seconds. Locks in the reward for your severity and timestamps you as first reporter.
Step two · Reproduction
Optional, and you can come back to it. This is what lets us put a cash number on a High or Critical.
Triage
We reproduce it, assign a severity, and tell you how we got there. You can argue with us about it.
Payout
Credits and plan months are guaranteed at your severity. Cash sits on top of High and Critical.
Scope

What counts, and what does not.

The out-of-scope list is not us being difficult. These are the reports that arrive without a working exploit behind them, and each one costs a day to rule out.

Areas in and out of scope for the RevOps.ai disclosure program
In scopeapp.revops.ai and everything inside the application
In scopeThe RevOps.ai API
In scopeAuthentication, billing, and credit accounting
In scopeIntegrations and webhooks we publish
In scopeAgent behavior, where you can show a concrete consequence
Limitedrevops.ai, this marketing site
Out of scopeMissing SPF, DKIM, or DMARC records
Out of scopeMissing security headers with no demonstrated exploit
Out of scopeClickjacking on pages with no state-changing action
Out of scopeSelf-XSS, or anything needing a pasted console payload
Out of scopeOutdated library versions with no working exploit path
Out of scopeRaw scanner output submitted without a proof of concept
Out of scopeRate limiting on unauthenticated, non-sensitive endpoints
Out of scopeDenial of service, load testing, resource exhaustion
Out of scopeSocial engineering, physical attacks, compromised devices
Out of scopeVulnerabilities in third-party services we do not control

If you can demonstrate real impact from something marked out of scope, send it anyway. A working exploit beats a category list. Our Acceptable Use Policy and Terms of Service still apply, except where they conflict with the safe harbor above. There, the safe harbor wins.

What happens next

You will not be left wondering.

These are timelines we can actually hold to, which is why they are not measured in hours. A missed promise is worse than a modest one.

2 business days
A human acknowledges your report and confirms your reference.
5 business days
We tell you whether we reproduced it, the severity we assigned, and why.
10 business days
Your reward is confirmed, including any cash bounty on a High or Critical.
Through the fix
We keep you posted, and credit you publicly when it ships if you want us to.
The fine print

The rest of the rules.

  • The first person to report a root cause is the one we reward. Duplicates get a genuine thank you and nothing else.
  • One reward per root cause, even where the same bug surfaces in several places.
  • Use test accounts. Do not access, change, or keep data that is not yours, and stop as soon as you have proved the point.
  • No automated scanning at volume against production, and nothing that degrades the service for anyone else.
  • Give us 90 days before publishing, or until the fix ships if that comes first. If you need a different timeline, ask and we will talk about it.
  • Current and former employees, contractors, and their immediate family are not eligible.
  • Cash amounts are discretionary and set at triage. The credits and plan months in the table are not: confirm a finding at a severity and we pay them. Rewards are subject to our Acceptable Use Policy, we cannot pay anyone in a country under applicable sanctions, and any tax is yours to handle.
FAQ

The questions researchers ask.

Will you take legal action if I report a bug?

No. If you follow this policy we consider your research authorized, we will not pursue legal action against you, we will not ask anyone else to, and we will say so in writing to any third party who asks. If a well-meaning mistake takes you slightly out of bounds, tell us what happened and we will work it out with you rather than escalate it.

Why is there no maximum cash bounty on this page?

Because we would be making it up. What a finding is worth depends on what it actually lets someone do, and nobody can judge that from a one-line summary. So the table is a floor: confirm a finding at a given severity and you get exactly what it says, every time. Cash sits on top for High and Critical, assessed once we can reproduce the issue.

Do I have to write the full report before I get anything?

No, and that is the point of splitting the form. Step one is four fields and takes about twenty seconds. That alone puts you in the queue, timestamps you as first reporter, and locks in the guaranteed reward for whatever severity we assign. Reproduction steps are step two, they are optional, and you can come back to them later. They exist because we can only put a cash figure on something we can reproduce.

How much cash will I actually get?

We set it at triage, based on impact, exploitability, and how much work your report saved us. A report we can reproduce from your steps is worth materially more to us than one we have to reverse engineer, and we price it that way. We would rather under-promise here and pay well than publish a headline number and haggle you down afterwards.

Can I publish what I found?

Yes, after 90 days, or as soon as the fix ships if that comes first. We are not going to ask you for an indefinite embargo. If you have a conference deadline or some other reason to need a different timeline, say so early and we will work with it rather than around it.

Do you need my real name?

Not to file a report. Any email address works, and you can stay anonymous in any public credit. We will need enough detail to actually get a payment to you before we can pay a cash bounty, but that conversation happens after triage, not before you tell us about the bug.

What if someone already reported it?

The first report of a root cause is the one we reward, and we will tell you honestly if yours was a duplicate, including roughly when the original landed. One reward per root cause, even where the same underlying bug shows up in several places.

Is the marketing site in scope?

Only partly. revops.ai is a mostly static marketing site, so header, cookie, and configuration findings on it are out of scope. Anything that touches a form handler, a redirect, or user data on this domain is in scope, and so is anything that gives you a foothold into the application. If you can demonstrate real impact, send it regardless of what the table says.

Four fields locks in your reward.

You do not need a write-up, a proof of concept, or your real name to start. Send the summary and we will take it from there.

Report a vulnerability

Or email security@revops.ai · Policy at /.well-known/security.txt

Report a Vulnerability - RevOps.ai