Vulnerability bug bounty program

If you are a security researcher interested in evaluating ReReady’s security, we welcome your insights. In fact, we offer a bounty on confirmed security issues that have not been previously reported.

Bounty by priority

We rely on the Bugcrowd vulnerability rating taxonomy to rate priority on a scale from P1 (highest) to P5 (lowest). We award the following bounties:

  • P1: $1,000
  • P2: $500
  • P3: $200
  • P4: $100
  • P5: Discretionary $50. (As P5 is “informational”, we will issue a $50 bounty if you report a vulnerability we weren’t aware of. For example, we are already aware our app supports “Concurrent Logins” so we will not issue a bounty for that.)

Researching vulnerabilities

Please use our sandbox environment.

Reporting a vulnerability

To report a vulnerability, please email support@reready.co to explain:

  • Vulnerability name (like “Cross-site scripting (XSS)”)
  • Replication instructions, and any other details
  • Recommended resolution(s)
  • Priority estimate (like “P3”)

We will reply within 5 business days.

Last updated August 15, 2026