Vulnerability disclosure & bounty program
At RMM Labs we take data security and privacy seriously. We operate a multi-database tenant isolation architecture to protect our users. We welcome coordinated vulnerability disclosures from ethical hackers and security researchers.
Program structure
Private program with quarterly budget caps
While this policy is public, financial rewards are currently prioritized for invited researchers testing our dedicated staging environments.
Our maximum bounty pool is capped at €3,000 per quarter. Bounties are awarded strictly on a first-come, first-served basis for unique, verified vulnerabilities. Once the quarterly pool is exhausted, valid bugs will be recognized via our Hall of Fame until the next budget cycle resets.
Target scope
Architecture focus & boundaries
In scope
- Staging / sandbox environment (URL provided to invited researchers)
- Routing, tenant switching, and custom domain mapping logic
- Tenant connection hijacking via subdomain, vanity domain spoofing, or custom host header manipulation
- Inertia data over-sharing — Vue components exposing hidden backend Eloquent model attributes or keys
- Cross-tenant BOLA / IDOR across parallel database structures
Out of scope
- Production environments or real client infrastructure
- Automated high-volume scanning tools (results in an immediate IP ban)
- Third-party infrastructure (e.g. Let's Encrypt API, AWS / cloud provider layer)
- Denial of Service (DoS / DDoS) or social engineering / phishing
We utilize Laravel 11, Inertia.js, and Vue. We explicitly request researchers to focus on logic gaps rather than standard framework features.
Reward matrix
Payouts by severity
| Severity | Definition | Payout |
|---|---|---|
| Critical (P1) | Unauthenticated cross-database access / Remote code execution | €1,500 |
| High (P2) | Total single-tenant admin takeover / Core routing table injection | €750 |
| Medium (P3) | Stored XSS bypassing Vue escaping / Sensitive API key leakage | €250 |
| Low (P4) | Informational leaks / Missing security headers | Hall of fame |
Rules of engagement
Legal safe harbor & requirements
Do no harm
Do not disrupt our systems or modify / delete data.
No public disclosure
Keep all details confidential until our engineering team deploys a patch and gives explicit permission to publish.
Provide a valid PoC
Submissions must include explicit step-by-step instructions or an exploit script demonstrating actual security impact. Automated scanner summaries will be rejected.
How to submit
Send your detailed Proof of Concept (PoC) to the address below. We aim to acknowledge your submission within 3 business days and provide a verification update within 7 business days.
Report a vulnerabilityThank you for helping keep our platform and our EU customers secure.