RootBounty connects organisations that want their systems tested ("companies") with independent security researchers ("researchers"). By creating an account you agree to these terms.
Accounts
- An account belongs to one person or one organisation and has one role: researcher or company. It cannot hold both.
- Two-factor authentication is mandatory. You are responsible for your authenticator, your recovery codes and your email inbox.
- Company accounts and every program are reviewed by RootBounty before they are published. We may decline them without giving reasons beyond those we record in the review.
Researchers
- Test only assets listed in scope of a program, and only in the ways its guidelines allow.
- No denial of service, social engineering, physical attacks, spam or access to data that is not yours beyond what is needed to prove the issue.
- Report through RootBounty and keep findings confidential until the program discloses them.
Companies
- You confirm you are authorised to invite testing of every asset you list.
- You respond to reports within the times you publish, and pay bounties you advertise for valid, in-scope findings.
- You do not take legal action against researchers acting in good faith under your guidelines (safe harbor).
Suspension
We may suspend accounts that break these terms, a program's guidelines or the law. Suspension ends every active session.