Railway Bug Bounty
Introduction
We recognize the important role that security researchers and our user community play in helping to keep Railway and our users secure.
If you have discovered a vulnerability in the Railway platform or any of its associated services, you may be eligible for a monetary reward.
Railway's Bug Bounty Program is operated by Bugcrowd. The program is currently invite-only, so you will need an invitation before you can submit a report.
Rewards
Reports are graded against Bugcrowd's Vulnerability Rating Taxonomy. The full program brief, including scope and reward ranges, is available inside the program once you have been invited.
Requesting an invitation
We plan to open the program more broadly in the future. For now, it remains invite-only.
To request an invitation, email bugbounty@railway.com with the email address on your Bugcrowd account and we will send you one.
Reporting a critical vulnerability
If you have found a critical vulnerability and you are not yet in the program, do not wait for an invitation. Email bugbounty@railway.com with the details and we will review it and route it to the right place as quickly as we can.
Disclosure
Please do not publicly disclose a vulnerability without our explicit review and consent. This applies whether or not the report results in a reward.