SRAA Bug Bounty Program

Policy and scope for security testing.

Scope of Operations (Scope)

In-Scope Targets

Only the following targets are authorized for testing:

  • /sraa
  • /sraa/*

Out-of-Scope Targets

Any assets not explicitly listed above are considered out of scope. This includes, but is not limited to:

  • /* (All other sites and services)

Testing outside the defined scope is a policy violation and may result in disqualification from the program.

Response Statistics

1 hours

Average time to first response

4 hours

Average time to triage

1 days, 7 hours

Average time to bounty

3 days, 20 hours

Average time from submission to bounty

1 weeks, 3 day

Average time to resolution