Rallyware · Vulnerability Disclosure

Rallyware Vulnerability Disclosure

Vulnerability disclosure

Rallyware runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanySales EnablementWorkforce EnablementLearning and DevelopmentPerformance ManagementGamificationDirect SellingEnterprise Software
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
ops@rallyware.com

Source

Vulnerability Disclosure

rallyware-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.rallyware.com/security-2
policy:
- https://www.rallyware.com/security-2
contact:
- ops@rallyware.com
program:
  type: bug bounty
  name: Bug Bounty Program
  url: https://www.rallyware.com/security-2
  rewards: true
  reward_model: >-
    "The researcher receives a reward according to the vulnerability category."
    No reward table, minimum, or maximum is published.
  platform: none
  platform_note: >-
    Self-run. No HackerOne, Bugcrowd, Intigriti or other third-party platform is
    used; reports go directly to the contact address by email.
  scope: >-
    "Security researchers can test our public services and products." No explicit
    in-scope/out-of-scope asset list is published.
  rules:
  - DoS/DDoS attacks are prohibited.
  - Social engineering is prohibited.
  - Physical intrusion is prohibited.
  - >-
    Responsible disclosure required — "the researcher is not allowed to publish
    details until the vulnerability is fixed." No coordinated-disclosure deadline is
    stated.
  stated_purpose:
  - Provide an additional layer of protection for products and services.
  - Create a transparent channel of communication with independent security researchers.
  - Receive information about potential risks in time to eliminate them.
  triage_commitment: >-
    "We promptly analyze the message, confirm the finding and determine the level of
    criticality." No SLA or response-time commitment is given.

related_practices:
- Annual independent penetration testing.
- Information Security Management System (ISMS), updated annually and reviewed
  through internal and external audits.
- Business continuity and disaster recovery plans, regularly tested.

security_txt:
  served: false
  path: /.well-known/security.txt
  status: 404
  probed: '2026-08-14'
  gap: >-
    Rallyware runs a real bug bounty with a published contact address but serves no
    RFC 9116 security.txt. A four-line file naming Contact: mailto:ops@rallyware.com
    and Policy: https://www.rallyware.com/security-2 would make the program
    machine-discoverable at zero cost. This is the single cheapest security-posture
    improvement available to this provider.

evidence:
- source: https://www.rallyware.com/security-2
  kind: disclosure page
  http_status: 200
  keywords:
  - bug bounty
  - vulnerability
  - responsible disclosure
  - security research
  - penetration testing
- source: https://www.rallyware.com/.well-known/security.txt
  kind: security.txt probe
  http_status: 404
note: >-
  The reporting address is published on the page behind Cloudflare email obfuscation
  (data-cfemail); it decodes to ops@rallyware.com. Recorded because it is the address
  Rallyware itself directs researchers to, in the sentence "If a vulnerability is
  discovered, they report it directly to ...".