Ryne Logo
Security at Ryne

Bug Bounty Program

Found a security flaw in Ryne? We want to hear about it before anyone else does. Report it responsibly and we'll reward you for making the platform safer for every student who relies on it.

How it works

Three steps from bug to bounty

1

Hunt

Poke at Ryne within the rules below. Look for vulnerabilities in authentication, payments, AI tools, or anywhere user data flows.

2

Report

Email us a clear write-up with reproduction steps, impact, and affected URLs. We acknowledge every valid report within 3 business days.

3

Get rewarded

Once we confirm and triage the issue, you get paid based on severity. We credit researchers who want recognition, and we fix fast.

Rewards

Paid by severity

Final amounts depend on impact, exploitability, and report quality. Exceptional reports can earn above the listed range.

Critical

$300 – $1,000

Remote code execution, SQL injection, full account takeover, exposed secrets, payment bypass

High

$100 – $300

Stored XSS, privilege escalation, IDOR exposing other users' data, auth logic flaws

Medium

$50 – $100

Reflected XSS, CSRF with real impact, coin/credit manipulation, sensitive info disclosure

Low

$10 – $50 or 1 year of Ryne Pro

Minor info leaks, security misconfigurations, issues requiring unlikely user interaction

Scope

What counts, what doesn't

In scope

  • ryne.ai and all of its subdomains
  • Authentication, sessions, and account management
  • Payments, subscriptions, and coin balances
  • AI tools: humanizer, chat, essay composer, editor, deep-check
  • The Ryne API and Chrome extension

Out of scope

  • Denial of service, rate-limit flooding, or spam
  • Social engineering or phishing of Ryne staff or users
  • Third-party services we don't control (Stripe, Supabase infrastructure)
  • Self-XSS, clickjacking on pages without sensitive actions
  • Reports from automated scanners without a proven exploit
  • Prompt-injection outputs with no security impact
Ground rules

Play fair, stay safe

Follow these rules and we consider your research authorized. We will not pursue legal action against good-faith security research that stays within them.

Test only your own accounts

Never access, modify, or destroy data that belongs to another user. Create test accounts instead.

Report privately, first

Send reports to contact@ryne.ai and give us 90 days to fix before any public disclosure.

Don't disrupt the service

No load testing, destructive payloads, or anything that degrades Ryne for other users.

First valid report wins

Duplicates go to whoever reported first. One reward per underlying root cause.

Found something?

Email contact@ryne.ai with reproduction steps, affected URLs, and impact. The clearer the report, the faster the payout.

Report a vulnerability