docs.range.org
Top 1M siteProgram Details
Range runs a bug bounty program that rewards security researchers who help protect our platform and customers. Submit vulnerabilities in any Range product or infrastructure to [email protected].
- Allows Disclosure
- Yes
- Disclosure Window
- 90 days
Payout Structure
Rules & Testing
Excluded Methods
In-Scope Domains
- range.org and all *.range.org subdomains
- Range platform, APIs (Risk, Data, Faraday), and dashboards
- Authentication and authorization flows
- Remote code execution, SQL injection, SSRF, and server-side template injection
- Broken access control, IDOR, and privilege escalation
- Authentication bypass and account takeover
- Sensitive data exposure and information disclosure
- Stored or reflected XSS with demonstrable impact
Out of Scope
stage.range.org and other non-production environments, Social engineering, phishing, or physical attacks, Denial of service (DoS/DDoS) and volumetric testing, Issues in third-party services we do not control, Reports from automated scanners without a working proof of concept, Best-practice recommendations without a demonstrable vulnerability, Missing security headers (CSP, HSTS, X-Frame-Options) without a demonstrated exploit, SPF, DKIM, or DMARC configuration issues, Self-XSS, clickjacking on pages without sensitive actions, and CSRF on logout or non-state-changing endpoints, Rate limiting or brute-force concerns without a clear impact path, Username or email enumeration, Vulnerabilities in outdated browsers or already-patched dependencies without a working proof of concept, Issues already known to the team or previously reported