If you believe you have found a security vulnerability in a Rain product or service, please report it to vdp@rain.xyz. This is the only channel for security reports: please do not use support channels, social media, or individual employees, and please do not post details publicly while an issue is unresolved.
To help us assess a report quickly, include the affected system, the steps to reproduce it, and what you observed.
Our security team reviews every report we receive. Where a finding is actionable we will follow up, and we may contact you for more detail. We are not able to respond individually to every submission. Rain does not currently operate a paid bug bounty program, and reports are not eligible for monetary rewards.
We ask that you take only the minimum action needed to demonstrate that an issue exists. Do not access, alter, or retain data that is not yours; do not disrupt or degrade our services; and do not move funds or transact on accounts or cards that are not yours. Where a finding is used destructively or for gain, including taking or retaining data, disrupting service, moving funds, selling or transferring the finding, or exploiting the issue publicly, that conduct falls outside this policy. We will not review or support such submissions, we treat them as security incidents, and Rain reserves all rights and remedies available to it.