generated: '2026-08-14' method: searched probe: true source: https://www.rallyware.com/security-2 policy: - https://www.rallyware.com/security-2 contact: - ops@rallyware.com program: type: bug bounty name: Bug Bounty Program url: https://www.rallyware.com/security-2 rewards: true reward_model: >- "The researcher receives a reward according to the vulnerability category." No reward table, minimum, or maximum is published. platform: none platform_note: >- Self-run. No HackerOne, Bugcrowd, Intigriti or other third-party platform is used; reports go directly to the contact address by email. scope: >- "Security researchers can test our public services and products." No explicit in-scope/out-of-scope asset list is published. rules: - DoS/DDoS attacks are prohibited. - Social engineering is prohibited. - Physical intrusion is prohibited. - >- Responsible disclosure required — "the researcher is not allowed to publish details until the vulnerability is fixed." No coordinated-disclosure deadline is stated. stated_purpose: - Provide an additional layer of protection for products and services. - Create a transparent channel of communication with independent security researchers. - Receive information about potential risks in time to eliminate them. triage_commitment: >- "We promptly analyze the message, confirm the finding and determine the level of criticality." No SLA or response-time commitment is given. related_practices: - Annual independent penetration testing. - Information Security Management System (ISMS), updated annually and reviewed through internal and external audits. - Business continuity and disaster recovery plans, regularly tested. security_txt: served: false path: /.well-known/security.txt status: 404 probed: '2026-08-14' gap: >- Rallyware runs a real bug bounty with a published contact address but serves no RFC 9116 security.txt. A four-line file naming Contact: mailto:ops@rallyware.com and Policy: https://www.rallyware.com/security-2 would make the program machine-discoverable at zero cost. This is the single cheapest security-posture improvement available to this provider. evidence: - source: https://www.rallyware.com/security-2 kind: disclosure page http_status: 200 keywords: - bug bounty - vulnerability - responsible disclosure - security research - penetration testing - source: https://www.rallyware.com/.well-known/security.txt kind: security.txt probe http_status: 404 note: >- The reporting address is published on the page behind Cloudflare email obfuscation (data-cfemail); it decodes to ops@rallyware.com. Recorded because it is the address Rallyware itself directs researchers to, in the sentence "If a vulnerability is discovered, they report it directly to ...".