Security
Vulnerability Disclosure Policy
Guidelines for security researchers participating in our bug bounty program. We value your contributions to keeping Rapidtrade secure.
Safe Harbor
Rapidtrade will not pursue legal action against security researchers who comply with the following guidelines:
Good Faith Testing
Conduct testing in good faith to identify and report vulnerabilities without causing harm to users or systems.
No Data Access
Do not access, modify, delete, or exfiltrate user data. If you accidentally access user data, stop immediately and report.
No Service Disruption
Avoid actions that could degrade service performance, availability, or integrity for other users.
Timely Reporting
Report vulnerabilities promptly through our official channels. Do not exploit vulnerabilities beyond proof of concept.
Coordinated Disclosure
Allow 90 days for remediation before public disclosure. Work with us on coordinated disclosure timing.
Single Account
Use only accounts you own or have explicit permission to test. Do not attempt to access other users' accounts.
Legal Authorization: This policy constitutes authorization to conduct security research under the Computer Fraud and Abuse Act (CFAA) and provides safe harbor under the Digital Millennium Copyright Act (DMCA) Β§1201(j). We will not pursue legal action against researchers who act in good faith pursuant to this policy.
Our Commitments
Rapid Response
- βAcknowledge receipt within 24 hours
- βProvide initial assessment within 72 hours
- βKeep you informed of remediation progress
- βNotify you when issues are resolved
Fair Compensation
- βPay bounties within 14 days of validation
- βDetermine payouts based on impact and quality
- βOffer bonuses for exceptional reports
- βNever reduce bounties for duplicate reports
Recognition
- βCredit in our Hall of Fame (with permission)
- βAnnual security researcher appreciation
- βReferences for employment (on request)
- βEarly access to new security features
Legal Protection
- βNo legal action for good faith research
- βDMCA safe harbor for security research
- βCFAA safe harbor provisions
- βWritten authorization available on request
Testing Guidelines
Allowed
- βTesting against your own accounts
- βManual testing and analysis
- βReviewing client-side JavaScript
- βTesting API endpoints with your credentials
- βUsing automated scanners with rate limiting
- βSocial engineering against yourself
Not Allowed
- ΓDenial of service attacks
- ΓAutomated high-volume scanning
- ΓPhysical security testing
- ΓSocial engineering against employees
- ΓTesting against other users' data
- ΓExploiting vulnerabilities in production
Program Scope
Web Applications
rapidtrade.orgHighapp.rapidtrade.orgCriticalstaging.rapidtrade.orgMediumbeta.rapidtrade.orgMediumAPIs
api.rapidtrade.org/v3/*Criticalapi.rapidtrade.org/v2/*Highws.rapidtrade.orgCriticalauth.rapidtrade.orgCriticalMobile Apps
iOS App (App Store)HighAndroid App (Play Store)HighiOS TestFlightMediumAndroid BetaMediumSmart Contracts
Verified contracts on EthereumCriticalVerified contracts on SolanaCriticalBridge contractsCriticalStaking contractsHighExclusions
The following issues are generally not eligible for bounty rewards:
Resources
Submit Report
Report a vulnerability
Hall of Fame
View recognized researchers
security.txt
Machine-readable policy
Questions about this policy? Contact us at security@rapidtrade.org