Legal · Updated 28 September 2026

Terms of use

RootBounty connects organisations that want their systems tested ("companies") with independent security researchers ("researchers"). By creating an account you agree to these terms.

Accounts

  • An account belongs to one person or one organisation and has one role: researcher or company. It cannot hold both.
  • Two-factor authentication is mandatory. You are responsible for your authenticator, your recovery codes and your email inbox.
  • Company accounts and every program are reviewed by RootBounty before they are published. We may decline them without giving reasons beyond those we record in the review.

Researchers

  • Test only assets listed in scope of a program, and only in the ways its guidelines allow.
  • No denial of service, social engineering, physical attacks, spam or access to data that is not yours beyond what is needed to prove the issue.
  • Report through RootBounty and keep findings confidential until the program discloses them.

Companies

  • You confirm you are authorised to invite testing of every asset you list.
  • You respond to reports within the times you publish, and pay bounties you advertise for valid, in-scope findings.
  • You do not take legal action against researchers acting in good faith under your guidelines (safe harbor).

Suspension

We may suspend accounts that break these terms, a program's guidelines or the law. Suspension ends every active session.