Bug Bounty Program
Help us secure RoadmapAI • Responsible Security Disclosure
At RoadmapAI, our community's safety and privacy are our highest priorities. We appreciate the efforts of security researchers and ethical hackers who help us maintain high standards of security.
1. Responsible Disclosure Rules
We expect security researchers to follow these guidelines to qualify for recognition or potential rewards:
- Do not attempt to access other users' private information or accounts.
- Do not execute denial of service (DoS/DDoS) attacks or degrade performance.
- Give us reasonable time to investigate and fix any reported vulnerability before publishing details.
- Do not use automated spamming tools, brute-forcing, or social engineering attacks.
- Only test against accounts and data you own or have explicit permission to test.
- Do not modify, delete, or exfiltrate any user data during testing.
2. In-Scope Domains
The following domains and applications are in scope for our bug bounty program:
- roadmapai.xyz — Main Application
Any subdomain or service not listed above is considered out of scope unless explicitly confirmed by our team.
3. Out of Scope Vulnerabilities
The following types of vulnerabilities are generally excluded from our program:
- Vulnerabilities requiring physical access to target devices.
- Spam, phishing, or social engineering techniques against our users or staff.
- Issues related to third-party integrations unless a direct exploit is present on our side.
- Vulnerabilities in old versions of libraries without active exploits or proof-of-concept.
- Self-XSS or attacks requiring significant user interaction with no realistic impact.
- Rate limiting on non-sensitive endpoints.
- Missing HTTP security headers without demonstrated exploitability.
4. Severity Classification
We classify vulnerabilities using the following tiers based on impact and exploitability (aligned with CVSS v3):
RCE, Auth bypass, Mass data leak
🎁 Monetary reward + Hall of Fame
Privilege escalation, IDOR, SQLi
🎁 Monetary reward or Premium subscription + Hall of Fame
Stored XSS, CSRF with impact, Info disclosure
🎁 Hall of Fame recognition
Reflected XSS (limited), Minor misconfigurations
🎁 Hall of Fame recognition (case-by-case)
Final severity classification is at RoadmapAI's sole discretion. Monetary reward amounts vary based on uniqueness, quality of report, and actual business impact.
5. Recognition and Rewards
Depending on the severity of the vulnerability, we may provide:
- Public listing in our Security Hall of Fame.
- Monetary rewards or premium subscriptions for eligible High / Critical severity findings.
Rewards are granted at RoadmapAI's discretion and are not guaranteed. Only the first valid report of a unique vulnerability is eligible for a reward — duplicate submissions will be acknowledged but will not qualify.
6. Response Timeline
We are committed to handling every report transparently and on time:
We confirm receipt of your report.
We triage, reproduce, and classify severity.
We patch the vulnerability and notify you.
Public disclosure agreed upon with the researcher.
7. Duplicate Submissions
- Only the first valid report of a unique vulnerability is eligible for recognition or reward.
- If your report is a duplicate, we will notify you and reference the original submission date.
- A report is considered valid only if it includes a clear description, steps to reproduce, and demonstrated impact.
8. Legal Safe Harbor
RoadmapAI will not pursue civil or criminal legal action against security researchers who discover and report vulnerabilities in good faith and in accordance with these guidelines. We consider such activities to be authorized and conducted for the benefit of the platform's security.
- This safe harbor applies only to researchers who follow all rules outlined in this program.
- Testing must be limited to in-scope targets and must not impact other users.
- RoadmapAI reserves the right to exclude any researcher who violates these terms from this protection.
- This safe harbor does not cover actions that are illegal under applicable laws independent of this program (e.g., unauthorized access to third-party systems).
Or email us directly at info@roadmapai.xyz
This program is subject to change at any time. Last updated: June 2026.