We would rather hear it from you than read about it somewhere else. Safe harbor for good-faith research, rewards published by severity rather than hinted at, and a reply from an actual person within two business days.
Safe harbor · Reply in 2 business days · No account needed
No. If you follow this policy, we consider your research authorized. We will not pursue legal action against you, we will not ask anyone else to, and we will say so in writing to any third party who asks. If a well-meaning mistake takes you slightly out of bounds, tell us what happened. We would rather work it out with you than escalate it.
In return: stay inside the scope below, use test accounts, do not go looking through data that is not yours, and give us 90 days before you publish, or until the fix ships if that comes first.
Confirm a finding at a given severity and you get what is listed, every time. We assign the severity, we explain how we got there, and you are welcome to argue with us about it.
| Severity | What that looks like | Reward |
|---|---|---|
| CriticalRemote code execution, data reachable across tenants, full account takeover. | Remote code execution, data reachable across tenants, full account takeover. | $2,500 in credits, plus 12 months of Agency.Plus cash, set at triage |
| HighAuthentication bypass, reading another account’s data, manipulating billing or credit balances. | Authentication bypass, reading another account’s data, manipulating billing or credit balances. | $1,000 in credits, plus 12 months of Team.Plus cash, set at triage |
| MediumStored cross-site scripting, server-side request forgery, information disclosure with a real consequence. | Stored cross-site scripting, server-side request forgery, information disclosure with a real consequence. | $250 in credits, plus 3 months of Growth. |
| LowReflected cross-site scripting with limited reach, logic flaws with bounded impact. | Reflected cross-site scripting with limited reach, logic flaws with bounded impact. | $50 in credits. |
| InformationalHardening suggestions with no demonstrated exploit path. | Hardening suggestions with no demonstrated exploit path. | Our thanks, and public credit when the fix ships if you want it. |
There is no maximum cash figure on this page because we would be making it up. What a finding is worth depends on what it actually lets someone do, and nobody can judge that from a one-line summary. Plenty of programs paper over that with an eye-catching number they rarely pay.
So we publish the floor instead, and we always honor it. Send the summary now to start the clock and lock in the reward for your severity. Add reproduction steps whenever you are ready, and we will price the rest properly.
Start with the summaryThe out-of-scope list is not us being difficult. These are the reports that arrive without a working exploit behind them, and each one costs a day to rule out.
| In scope | app.revops.ai and everything inside the application |
|---|---|
| In scope | The RevOps.ai API |
| In scope | Authentication, billing, and credit accounting |
| In scope | Integrations and webhooks we publish |
| In scope | Agent behavior, where you can show a concrete consequence |
| Limited | revops.ai, this marketing site |
| Out of scope | Missing SPF, DKIM, or DMARC records |
| Out of scope | Missing security headers with no demonstrated exploit |
| Out of scope | Clickjacking on pages with no state-changing action |
| Out of scope | Self-XSS, or anything needing a pasted console payload |
| Out of scope | Outdated library versions with no working exploit path |
| Out of scope | Raw scanner output submitted without a proof of concept |
| Out of scope | Rate limiting on unauthenticated, non-sensitive endpoints |
| Out of scope | Denial of service, load testing, resource exhaustion |
| Out of scope | Social engineering, physical attacks, compromised devices |
| Out of scope | Vulnerabilities in third-party services we do not control |
If you can demonstrate real impact from something marked out of scope, send it anyway. A working exploit beats a category list. Our Acceptable Use Policy and Terms of Service still apply, except where they conflict with the safe harbor above. There, the safe harbor wins.
These are timelines we can actually hold to, which is why they are not measured in hours. A missed promise is worse than a modest one.
No. If you follow this policy we consider your research authorized, we will not pursue legal action against you, we will not ask anyone else to, and we will say so in writing to any third party who asks. If a well-meaning mistake takes you slightly out of bounds, tell us what happened and we will work it out with you rather than escalate it.
Because we would be making it up. What a finding is worth depends on what it actually lets someone do, and nobody can judge that from a one-line summary. So the table is a floor: confirm a finding at a given severity and you get exactly what it says, every time. Cash sits on top for High and Critical, assessed once we can reproduce the issue.
No, and that is the point of splitting the form. Step one is four fields and takes about twenty seconds. That alone puts you in the queue, timestamps you as first reporter, and locks in the guaranteed reward for whatever severity we assign. Reproduction steps are step two, they are optional, and you can come back to them later. They exist because we can only put a cash figure on something we can reproduce.
We set it at triage, based on impact, exploitability, and how much work your report saved us. A report we can reproduce from your steps is worth materially more to us than one we have to reverse engineer, and we price it that way. We would rather under-promise here and pay well than publish a headline number and haggle you down afterwards.
Yes, after 90 days, or as soon as the fix ships if that comes first. We are not going to ask you for an indefinite embargo. If you have a conference deadline or some other reason to need a different timeline, say so early and we will work with it rather than around it.
Not to file a report. Any email address works, and you can stay anonymous in any public credit. We will need enough detail to actually get a payment to you before we can pay a cash bounty, but that conversation happens after triage, not before you tell us about the bug.
The first report of a root cause is the one we reward, and we will tell you honestly if yours was a duplicate, including roughly when the original landed. One reward per root cause, even where the same underlying bug shows up in several places.
Only partly. revops.ai is a mostly static marketing site, so header, cookie, and configuration findings on it are out of scope. Anything that touches a form handler, a redirect, or user data on this domain is in scope, and so is anything that gives you a foothold into the application. If you can demonstrate real impact, send it regardless of what the table says.
You do not need a write-up, a proof of concept, or your real name to start. Send the summary and we will take it from there.
Report a vulnerabilityOr email security@revops.ai · Policy at /.well-known/security.txt