RAW STRIX BUG BOUNTY

Find a bug. Get rewarded.

Found a security issue in Raw Strix? Report it here. We reward valid findings by severity and list researchers in our Hall of Fame.

Rewards

Critical

₹15,000–₹50,000

High

₹5,000–₹15,000

Medium

₹1,500–₹5,000

Low

₹500–₹1,500

The final amount depends on the real impact and the quality of the report. Paid by UPI or bank transfer. Valid reports also earn a place in the Hall of Fame.

In scope

  • rawstrix.com

    Website, accounts, dashboard and admin

  • bugbounty.rawstrix.com

    This program

  • demo.rawstrix.com

    The demo CTF platform

  • *.rawstrix.com event sites

    Customer event sites, only with an account you own

Out of scope

  • status.rawstrix.com
  • Denial of service and load testing
  • Social engineering, phishing, physical attacks
  • Findings from automated scanners without a working proof
  • Missing security headers or best practices with no demonstrated impact
  • Self-XSS, clickjacking on pages without sensitive actions, logout CSRF
  • Rate limiting on non-sensitive actions
  • CTF challenges themselves (finding flags is the game, not a bug)

Rules

  1. Only test against accounts you own or the public demo logins.
  2. Don't access, change or delete other people's data. Stop and report as soon as you see someone else's data.
  3. No denial of service, spam or automated scanning that degrades the service.
  4. Give us reasonable time to fix before telling anyone else.
  5. One issue per report. The first valid report of an issue gets the reward.
  6. Follow these rules and we won't pursue legal action for your research.