#Bug Bounty Program

7 messages · Page 1 of 1 (latest)

lofty ravine
#

Hi there, I notified you about a security vulnerability I discovered via email, but I haven't received a response from your team yet. It's been 10 days.

Thanks.

cunning cargoBOT
#

Project ID: N/A

#

We recognize the important role that security researchers and our user community play in helping to keep Railway and our users secure. If you have discovered a site or product vulnerability, you may be eligible for a monetary award in accordance with the terms and conditions of our Bug Bounty Program. Please submit your bug reports to [email protected].

lofty ravine
#

N/A

leaden lintel
#

cc @sterile badger @runic burrow

sterile badger
#

Hey @lofty ravine - sorry about that. The page says 30 days but honestly we should be doing better. Can you send the disclosure to [email protected]?

#

I can review it first thing my morning