Found a vulnerability?
If you've found a security issue in something we develop or operate, tell us. We triage every good-faith report and coordinate the fix with the responsible team.
Bug bounty
Our bug bounty pays for valid, previously-unreported vulnerabilities — scaled by severity and impact.
Prefer recognition over a payout? We credit researchers who want it. Either way, every good-faith report gets a response.
The fine print
Rewards are paid only for vulnerabilities in systems and code for which RocketParts is responsible — applications we build or operate. Eligibility and amounts are determined solely by RocketParts, require our confirmation of the issue, and are subject to authorization from the affected client. Issues in client-owned infrastructure, third-party services and dependencies, or systems RocketParts does not develop or manage are out of scope and not eligible. No reward is guaranteed.Scope
In scope
- ✓ Applications and services RocketParts builds or operates for clients
- ✓ Code and infrastructure under RocketParts' direct management
- ✓ This website, rocketparts.io
Out of scope
- × Client-owned infrastructure and accounts we don't manage
- × Third-party services, platforms, and dependencies
- × Volumetric DoS/DDoS, spam, and social engineering
- × Findings requiring physical access or a lost/stolen device
Rules of engagement & safe harbor
We support good-faith security research and will not pursue legal action against researchers who follow this policy. When testing, please:
Stay in scope
Only test systems within scope, and stop as soon as you've confirmed an issue.
Protect data
Don't access, modify, or exfiltrate data that isn't yours. Use test accounts where possible.
Do no harm
Avoid privacy violations, service degradation, and destruction of data.
Disclose responsibly
Give us a reasonable chance to remediate, and don't disclose publicly until we confirm the fix.
Submit a report
The more detail you share, the faster we can validate and fix it.