docs.range.org

docs.range.org

Top 1M site
Bug BountyActiveBounty Full Safe Harbor USD $250 - $10,000

Program Details

Range runs a bug bounty program that rewards security researchers who help protect our platform and customers. Submit vulnerabilities in any Range product or infrastructure to [email protected].

Allows Disclosure
Yes
Disclosure Window
90 days

Payout Structure

Critical USD $10,000
High USD $1,000
Medium USD $5,000
Low USD $250

Rules & Testing

Excluded Methods

DosSocial EngineeringPhishingPhysical AccessAutomated Scanning

In-Scope Domains

  • range.org and all *.range.org subdomains
  • Range platform, APIs (Risk, Data, Faraday), and dashboards
  • Authentication and authorization flows
  • Remote code execution, SQL injection, SSRF, and server-side template injection
  • Broken access control, IDOR, and privilege escalation
  • Authentication bypass and account takeover
  • Sensitive data exposure and information disclosure
  • Stored or reflected XSS with demonstrable impact

Out of Scope

stage.range.org and other non-production environments, Social engineering, phishing, or physical attacks, Denial of service (DoS/DDoS) and volumetric testing, Issues in third-party services we do not control, Reports from automated scanners without a working proof of concept, Best-practice recommendations without a demonstrable vulnerability, Missing security headers (CSP, HSTS, X-Frame-Options) without a demonstrated exploit, SPF, DKIM, or DMARC configuration issues, Self-XSS, clickjacking on pages without sensitive actions, and CSRF on logout or non-state-changing endpoints, Rate limiting or brute-force concerns without a clear impact path, Username or email enumeration, Vulnerabilities in outdated browsers or already-patched dependencies without a working proof of concept, Issues already known to the team or previously reported