# Responsible disclosure

As part of our responsible disclosure policy, we partner with <u>**HackerOne**</u> to support researchers and continue to bring you the most secure environment possible.

## Our approach

Primarily, we do active threat hunting and monitoring as part of our risk management program. We also invite security researchers at-large to identify and report security flaws. We offer compensation for finding notable issues that haven’t been reported.

## How to participate

Before and during testing against our environment, [visit the HackerOne site](https://hackerone.com/redox_bbp?type=team) to:

- Review the program details brief. Pay special attention to what’s considered in-scope and out-of-scope targets. By identifying these critical issues, you’re helping us make sure that Redox remains stable for all of our customers.
- Submit any bug reports. Issues reported outside of HackerOne are ineligible for compensation.
