RAW STRIX BUG BOUNTY
Find a bug. Get rewarded.
Found a security issue in Raw Strix? Report it here. We reward valid findings by severity and list researchers in our Hall of Fame.
Rewards
₹15,000–₹50,000
₹5,000–₹15,000
₹1,500–₹5,000
₹500–₹1,500
The final amount depends on the real impact and the quality of the report. Paid by UPI or bank transfer. Valid reports also earn a place in the Hall of Fame.
In scope
rawstrix.com
Website, accounts, dashboard and admin
bugbounty.rawstrix.com
This program
demo.rawstrix.com
The demo CTF platform
*.rawstrix.com event sites
Customer event sites, only with an account you own
Out of scope
- status.rawstrix.com
- Denial of service and load testing
- Social engineering, phishing, physical attacks
- Findings from automated scanners without a working proof
- Missing security headers or best practices with no demonstrated impact
- Self-XSS, clickjacking on pages without sensitive actions, logout CSRF
- Rate limiting on non-sensitive actions
- CTF challenges themselves (finding flags is the game, not a bug)
Rules
- Only test against accounts you own or the public demo logins.
- Don't access, change or delete other people's data. Stop and report as soon as you see someone else's data.
- No denial of service, spam or automated scanning that degrades the service.
- Give us reasonable time to fix before telling anyone else.
- One issue per report. The first valid report of an issue gets the reward.
- Follow these rules and we won't pursue legal action for your research.