Bug Bounty Program
Found a security flaw in Ryne? We want to hear about it before anyone else does. Report it responsibly and we'll reward you for making the platform safer for every student who relies on it.
Three steps from bug to bounty
Hunt
Poke at Ryne within the rules below. Look for vulnerabilities in authentication, payments, AI tools, or anywhere user data flows.
Report
Email us a clear write-up with reproduction steps, impact, and affected URLs. We acknowledge every valid report within 3 business days.
Get rewarded
Once we confirm and triage the issue, you get paid based on severity. We credit researchers who want recognition, and we fix fast.
Paid by severity
Final amounts depend on impact, exploitability, and report quality. Exceptional reports can earn above the listed range.
Critical
Remote code execution, SQL injection, full account takeover, exposed secrets, payment bypass
High
Stored XSS, privilege escalation, IDOR exposing other users' data, auth logic flaws
Medium
Reflected XSS, CSRF with real impact, coin/credit manipulation, sensitive info disclosure
Low
Minor info leaks, security misconfigurations, issues requiring unlikely user interaction
What counts, what doesn't
In scope
- ryne.ai and all of its subdomains
- Authentication, sessions, and account management
- Payments, subscriptions, and coin balances
- AI tools: humanizer, chat, essay composer, editor, deep-check
- The Ryne API and Chrome extension
Out of scope
- Denial of service, rate-limit flooding, or spam
- Social engineering or phishing of Ryne staff or users
- Third-party services we don't control (Stripe, Supabase infrastructure)
- Self-XSS, clickjacking on pages without sensitive actions
- Reports from automated scanners without a proven exploit
- Prompt-injection outputs with no security impact
Play fair, stay safe
Follow these rules and we consider your research authorized. We will not pursue legal action against good-faith security research that stays within them.
Test only your own accounts
Never access, modify, or destroy data that belongs to another user. Create test accounts instead.
Report privately, first
Send reports to contact@ryne.ai and give us 90 days to fix before any public disclosure.
Don't disrupt the service
No load testing, destructive payloads, or anything that degrades Ryne for other users.
First valid report wins
Duplicates go to whoever reported first. One reward per underlying root cause.
Found something?
Email contact@ryne.ai with reproduction steps, affected URLs, and impact. The clearer the report, the faster the payout.
Report a vulnerability