Railway Bug Bounty

Introduction

We recognize the important role that security researchers and our user community play in helping to keep Railway and our users secure.

If you have discovered a vulnerability in the Railway platform or any of its associated services, you may be eligible for a monetary reward.

Railway's Bug Bounty Program is operated by Bugcrowd. The program is currently invite-only, so you will need an invitation before you can submit a report.

Rewards

Reports are graded against Bugcrowd's Vulnerability Rating Taxonomy. The full program brief, including scope and reward ranges, is available inside the program once you have been invited.

Requesting an invitation

We plan to open the program more broadly in the future. For now, it remains invite-only.

To request an invitation, email bugbounty@railway.com with the email address on your Bugcrowd account and we will send you one.

Reporting a critical vulnerability

If you have found a critical vulnerability and you are not yet in the program, do not wait for an invitation. Email bugbounty@railway.com with the details and we will review it and route it to the right place as quickly as we can.

Disclosure

Please do not publicly disclose a vulnerability without our explicit review and consent. This applies whether or not the report results in a reward.