In scope
- sandbox.racinage.com
- Authenticated account, family, API, and plugin workflows
- Publisher workflows and documentation replicas
- Participating third-party plugins shown below
Coordinated vulnerability disclosure
Approved developers can investigate configured sandbox assets, submit encrypted reports, collaborate privately with the security team, and receive rewards for accepted findings.
Good-faith research is authorized only inside the isolated bounty sandbox. Production permits passive observation; the security team performs production confirmation.
CVSS v4 is the technical baseline. Racinage applies a documented business-impact adjustment before the final award.
Racinage will not initiate legal action for accidental, good-faith violations of the current policy when the researcher stops, reports promptly, protects data, and cooperates on remediation.
Researchers may appear by alias or anonymously after remediation or approved disclosure. Reward amounts remain private by default.
Approved acknowledgments will appear here after remediation or disclosure.
Concise answers to the eligibility, scope, and payout questions researchers ask most often.
Approved developers with verified email, enabled two-factor authentication, legal-majority attestation, and accepted current terms.
Only on explicitly listed sandbox.racinage.com assets. Production is passive-observation only, and all administrative routes are excluded.
After validation, within 30 calendar days after identity, jurisdiction, tax, and payout-profile checks pass.