Covering Xcellerate RMM and Xcellerate OPS

Vulnerability disclosure & bounty program

At RMM Labs we take data security and privacy seriously. We operate a multi-database tenant isolation architecture to protect our users. We welcome coordinated vulnerability disclosures from ethical hackers and security researchers.

Program structure

Private program with quarterly budget caps

While this policy is public, financial rewards are currently prioritized for invited researchers testing our dedicated staging environments.

Our maximum bounty pool is capped at €3,000 per quarter. Bounties are awarded strictly on a first-come, first-served basis for unique, verified vulnerabilities. Once the quarterly pool is exhausted, valid bugs will be recognized via our Hall of Fame until the next budget cycle resets.

Target scope

Architecture focus & boundaries

In scope

  • Staging / sandbox environment (URL provided to invited researchers)
  • Routing, tenant switching, and custom domain mapping logic
  • Tenant connection hijacking via subdomain, vanity domain spoofing, or custom host header manipulation
  • Inertia data over-sharing — Vue components exposing hidden backend Eloquent model attributes or keys
  • Cross-tenant BOLA / IDOR across parallel database structures

Out of scope

  • Production environments or real client infrastructure
  • Automated high-volume scanning tools (results in an immediate IP ban)
  • Third-party infrastructure (e.g. Let's Encrypt API, AWS / cloud provider layer)
  • Denial of Service (DoS / DDoS) or social engineering / phishing

We utilize Laravel 11, Inertia.js, and Vue. We explicitly request researchers to focus on logic gaps rather than standard framework features.

Reward matrix

Payouts by severity

SeverityDefinitionPayout
Critical (P1)Unauthenticated cross-database access / Remote code execution€1,500
High (P2)Total single-tenant admin takeover / Core routing table injection€750
Medium (P3)Stored XSS bypassing Vue escaping / Sensitive API key leakage€250
Low (P4)Informational leaks / Missing security headersHall of fame

Rules of engagement

Legal safe harbor & requirements

  • Do no harm

    Do not disrupt our systems or modify / delete data.

  • No public disclosure

    Keep all details confidential until our engineering team deploys a patch and gives explicit permission to publish.

  • Provide a valid PoC

    Submissions must include explicit step-by-step instructions or an exploit script demonstrating actual security impact. Automated scanner summaries will be rejected.

How to submit

Send your detailed Proof of Concept (PoC) to the address below. We aim to acknowledge your submission within 3 business days and provide a verification update within 7 business days.

Report a vulnerability

Thank you for helping keep our platform and our EU customers secure.