We welcome careful, good-faith security research that helps protect AlphaRank and its users. This policy explains what to test, what to avoid, and how to report an issue privately.
What to include
- A short description of the issue and its likely impact.
- Clear reproduction steps, affected URLs, and any required test account details.
- The smallest safe proof needed to show the issue. Redact access tokens, private keys, personal data, and other secrets.
- A way to contact you and whether you want public credit.
We aim to acknowledge reports within three business days and provide an initial triage update within ten business days. Complex issues can take longer; we will try to keep you informed.
Scope
AlphaRank-owned production web applications, APIs, and infrastructure under alpharank.trade are in scope. AlphaRank’s scoring, authorization, account isolation, receipts, leaderboards, webhooks, and release controls are especially important.
Third-party services and infrastructure not owned by AlphaRank—including Clerk, Stripe, AWS, market-data providers, social platforms, and researchers’ own systems—are out of scope. Report vulnerabilities in those services to their owners.
Research rules
- Use accounts and data you own or have explicit permission to access.
- Stop after proving the issue with the minimum access necessary.
- Do not exfiltrate, retain, alter, or publicly disclose another person’s data.
- Do not use denial of service, automated high-volume traffic, spam, social engineering, phishing, malware, persistence, or physical attacks.
- Do not manipulate markets, execute trades, move funds, or attempt to access wallets, private keys, seed phrases, or custody systems.
- Do not disrupt AlphaRank or its providers, and do not degrade availability for other users.
- Keep the issue confidential while we investigate and agree on a reasonable disclosure timeline.
If you encounter personal data, credentials, or secrets unexpectedly, stop, do not save or share them, and report the exposure immediately.
Good-faith safe harbor
If your research follows this policy, is intended to improve security, and avoids harm, AlphaRank will consider it authorized security research and will not initiate legal action against you for the research. If a third party initiates action related to compliant research, we will clarify that your work followed this policy where we are able to do so.
This safe harbor does not authorize violating other people’s rights or systems, and it does not bind independent third parties. If you are unsure whether a test is safe or in scope, contact us before testing.
Rewards and disclosure
This is a vulnerability disclosure program, not a bug bounty. Reports do not create a right to payment. Any reward must be agreed to by AlphaRank in writing before it is earned.
We will work toward a fix based on severity and coordinate public credit or disclosure when appropriate. Please give us a reasonable opportunity to investigate and remediate before publishing technical details.