Bounty Terms
Data security is a top priority for Route, and Route believes that working with skilled security researchers can identify weaknesses in any technology. If you believe you've found a security vulnerability in Route’s service, please don't hesitate to notify us. We will work with you to resolve the issue promptly.
Refer to route.gerobug.com/submit for submitting your findings.
Payouts for disclosed vulnerabilities will be made available after the issue has been triaged and the submitter successfully returns the applicable tax form(s).
- US Citizens, Form W-9
- Non US Citizens, Form W-8BEN
Route reserves the right to decide whether to offer monetary rewards for such reports based on risk, impact, and other considerations. You must initially satisfy the following criteria in order to be eligible for a bounty:
- We determine bounty amounts based on a variety of factors, including (but not limited to) impact, ease of exploitation and quality of the report.
- Although we strive to pay comparable sums for comparable concerns, bounty amounts and qualifying issues may alter over time. Rewards from the past may not always imply rewards of a similar magnitude in the future.
- In the event of duplicate reports, the first researcher to submit a legitimate Bug Bounty Report will get the compensation. (We are not obligated to disclose the specifics of the Bug Bounty Report).
Thank you for helping to keep Route and our users safe!
In Scope
- *.route.com
Out of Scope
- 3rd Party Apps and Plugins
- Spamming
- Attacks which require human interactions (Social Engineering)
- Attacks which require physical access to a certain resource
- Attacks which will take down the infrastructure (DoS / DDoS)
Responsible Disclosure Policy
We thank you for your effort and give you permission to share or publish the vulnerabilities you discovered. You can consult the disclosure statement below:
- Provide us with a reasonable amount of time to resolve the issue before disclosing it to the public or a third party. We aim to resolve critical issues within 72 hours of disclosure.
- Make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Route service. Please only interact with accounts you own or for which you have explicit permission from the account holder.
Report Guidelines
We may revise these guidelines from time to time. The most current version of the guidelines will always be updated and available in this article:
- Make sure you read and understand the "In Scope" and "Out Scope" of this bug bounty program.
- If you mistakenly cause a privacy violation or disruption (such as accessing account data, service configurations or other personal information) while investigating an problem, you must indicate this in your report.
- Use test accounts while examining issues. You can use a real account if you are unable to recreate an issue with a test account (except for automated testing).
- Avoid contacting / interact with an individual account (which includes modifying or accessing data from the account) if the account owner has not consented to such actions.
- Do not intentionally exploit a security flaw you find or violate any other applicable laws or regulations, including (but not limited to) laws and regulations prohibiting the unauthorised access to data.
FAQ
Q: What if I found a vulnerability, but I don't know how to exploit it?
A: We expect that vulnerability reports sent to us have a valid attack scenario to qualify for a reward, and we consider it as a critical step when doing vulnerability research.
Q: Who determines whether my report is eligible for a reward?
A: The reward panel consists of the members of the Route Security Team and Gero Security Team.
Q: How much is the reward?
A: Reward amounts are decided based on the maximum impact of the vulnerability, and the panel is willing to reconsider a reward amount, based on new information (such as a chain of bugs, or a revised attack scenario).
Q: When will reward be paid?
A: Payouts for disclosed vulnerabilities will be made available after the issue has been triaged and the submitter successfully returns the applicable tax form(s).
