Racinage
Francais

Security research

Bug Bounty Program

Last updated 2026-08-07T07:02:07+00:00

Approved Racinage developers can test isolated sandbox replicas, report vulnerabilities through an encrypted workspace, and receive private awards for accepted findings.

Launch status: The program remains closed until the isolated sandbox, file scanner, encrypted storage, Commerce wallet, payout controls, and acceptance tests are ready. Production permits passive observation only.

Program overview and eligibility

Participation requires an active approved developer account, verified email address, enabled two-factor authentication, legal-majority attestation, and acceptance of the current terms. Identity, jurisdiction, tax, and a verified encrypted payout profile are required only before a monetary payout.

The public policy is available at plugins.racinage.com/bug-bounty. Eligible researchers use Manage > Bug Bounty for drafts, submissions, discussions, awards, sanctions, appeals, and Hall of Fame preferences.

Testing scope and excluded assets

Active testing is authorized only on assets explicitly listed in the isolated sandbox.racinage.com program. Replicas may cover user-facing account, family, API, plugin, publisher, and documentation workflows. A third-party plugin is in scope only when its publisher has activated and prefunded a program.

Always out of scope: /admin7839, every administrative route and endpoint, internal tools, denial of service, social engineering, physical attacks, persistence, spam, privacy invasion, destructive testing, production data extraction, and unrelated third-party services.

Production systems permit passive observation only. Stop testing when sensitive data, unexpected impact, or an unlisted system is encountered. Racinage security administrators perform any production confirmation.

Safe harbor and prohibited activity

Good-faith research performed within the published policy is authorized. Racinage will not initiate legal action for accidental policy violations when the researcher stops, reports promptly, minimizes and protects data, and cooperates with remediation. This safe harbor does not authorize unlawful conduct or testing outside Racinage-owned or explicitly participating assets.

The policy follows coordinated disclosure principles reflected in ISO/IEC 29147 and the US Department of Justice Vulnerability Disclosure Policy. Report privately and do not disclose a case until remediation or written disclosure approval.

Sandbox registration and reset

After eligibility is confirmed, the researcher workspace displays available sandbox programs and assets. Sandbox accounts, database content, uploads, secrets, mail, and payments are synthetic and isolated from production. Sandbox cookies are not shared with production. Use the workspace reset request when test data becomes unusable; do not attempt to reach production resources from the sandbox.

Preparing a report and evidence

Include the affected program, asset and version, vulnerability class, prerequisites, exact reproduction steps, impact, suggested severity, remediation suggestion, and any disclosure conflict. One clear issue per report makes triage faster. The earliest actionable and reproducible report receives duplicate priority.

Evidence may be Markdown, text, JSON, PDF, WebP, JPEG, PNG, MP4, or WebM within the displayed limit. Archives, scripts, executables, active documents, and unsupported formats are rejected. Files remain private, are scanned before reviewer access, and are streamed only after authorization.

Submission immediately creates an in-app receipt, interface notification, detail-free email, and downloadable case receipt. Every submission snapshots the accepted policy, scope, reward table, safe-harbor terms, and disclosure terms. Revisions and private case discussions are preserved.

Severity and rewards

CVSS v4 is the technical baseline. Racinage then records a business-impact adjustment based on affected users, authorization boundaries, data sensitivity, exploit reliability, and platform exposure. Default private awards are USD 5-20 for Low, USD 50-100 for Medium, USD 150-250 for High, and USD 300-500 for Critical. A documented override is required outside the active program range.

Acknowledgment is targeted within 3 business days, triage within 7 business days, and updates weekly, consistent with established intake guidance. Remediation targets are 15 days for Critical, 30 for High, 60 for Medium, and 90 for Low.

Payout verification, methods, and timing

An award becomes payable after validation, not after remediation. Racinage reserves the exact award from the program wallet when the report is accepted. The award remains owed if the program later pauses, hides, closes, or becomes underfunded.

Payment uses pawaPay or an approved manual method within 30 calendar days after identity, jurisdiction, tax, and verified payout-profile checks pass. Payout details reuse the encrypted developer payout profile. Bug Bounty ledgers remain separate from affiliate and plugin-revenue accounting. Reward amounts are private by default.

Coordinated disclosure and Hall of Fame

Reports remain private until remediation or explicit disclosure approval. The default coordinated-disclosure target is 90 days, with documented extensions when needed, following established coordinated-disclosure practice such as Google Project Zero's disclosure policy. Only authorized security administrators may confirm a report on production or publish an advisory.

After remediation or approved disclosure, researchers may choose an alias, anonymous recognition, or no Hall of Fame listing. Later duplicates are linked privately without exposing the original reporter or report.

Sanctions, appeals, privacy, and retention

Default limits are 5 submissions in a rolling 24-hour period and 20 unresolved reports. Invalid, informative, and duplicate outcomes are not abuse by themselves. Misuse may receive a warning, 7-day, 30-day, or 90-day suspension, or a permanent Bug Bounty ban. One appeal may be filed within 14 days.

Raw evidence is deleted two years after final closure unless a legal hold applies. Minimized case, decision, financial, sanction, and audit metadata is retained for seven years. Approved public advisories may be retained as long as needed.

Publisher program setup and wallet funding

A third-party publisher program must define exact plugin versions, dependencies, scope, exclusions, rewards, and testing instructions. It cannot activate until its separate USD wallet has available funds equal to at least one maximum Critical award. Intake pauses automatically below that threshold.

Wallet funding uses reconciled Commerce orders through FastSpring, pawaPay, or an enabled manual method. The append-only ledger records openings, refills, adjustments, reservations, releases, awards, refunds, reversals, and chargebacks. Publisher refunds require a 14-day cooling period and no pending reports, reservations, disputes, payouts, or chargebacks.

Security contact

Use the encrypted researcher workspace for vulnerability details. For policy questions that contain no vulnerability evidence, contact security@racinage.com. Discovery metadata is published at racinage.com/.well-known/security.txt.