---
title: Railway Bug Bounty
description: Railway's Bug Bounty Program is operated by Bugcrowd and is invite-only. Report a vulnerability in the Railway platform and you may be eligible for a reward.
url: https://railway.com/bug-bounty
---

# Railway Bug Bounty

We recognize the important role that security researchers and our user community play in helping to keep Railway and our users secure.

If you have discovered a vulnerability in the Railway platform or any of its associated services, you may be eligible for a monetary reward.

Railway's Bug Bounty Program is operated by Bugcrowd (https://www.bugcrowd.com/). The program is currently invite-only, so you will need an invitation before you can submit a report.

## Rewards

Reports are graded against Bugcrowd's Vulnerability Rating Taxonomy (https://bugcrowd.com/vulnerability-rating-taxonomy). The full program brief, including scope and reward ranges, is available inside the program once you have been invited.

## Requesting an invitation

We plan to open the program more broadly in the future. For now, it remains invite-only.

To request an invitation, email bugbounty@railway.com with the email address on your Bugcrowd account and we will send you one.

## Reporting a critical vulnerability

If you have found a critical vulnerability and you are not yet in the program, do not wait for an invitation. Email bugbounty@railway.com with the details and we will review it and route it to the right place as quickly as we can.

## Disclosure

Please do not publicly disclose a vulnerability without our explicit review and consent. This applies whether or not the report results in a reward.

## Related

- Security overview: https://railway.com/security
- Terms of service: https://railway.com/legal/terms
- Privacy policy: https://railway.com/legal/privacy

---

Open this page in a browser:
<a href="https://railway.com/bug-bounty">https://railway.com/bug-bounty</a>
[https://railway.com/bug-bounty](https://railway.com/bug-bounty)
