Run on Realms
FeaturesSeason Soon
Waitlist

Security & Vulnerability Disclosure

Last updated: 31 May 2026

1. Our Commitment

Run on Realms (“ROR”), operated by Mobinsons Ventures Private Limited, takes the security of our users and infrastructure seriously. We welcome and appreciate the work of security researchers who identify and responsibly disclose vulnerabilities, helping us keep the service safe for everyone.

This policy describes how to report a security issue and what you can expect in return. It is also published as a machine-readable file at /.well-known/security.txt per RFC 9116.

2. Reporting a Vulnerability

Please email [email protected] with the subject line “Security Disclosure: [brief description]”.

Include:

  • A description of the vulnerability and its impact
  • Steps to reproduce (with screenshots, video, or PoC code if applicable)
  • The affected URL, endpoint, or app screen
  • Your name and contact info (for follow-up — we can credit you publicly if you wish, or stay anonymous if you prefer)

If the vulnerability is sensitive (e.g., a credential leak, mass data exposure, or active exploitation), please use end-to-end encrypted communication. We can provide a PGP key on request.

3. What You Can Expect From Us

  • Acknowledgement within 48 hours of receiving your report
  • Initial triage and severity assessment within 5 business days
  • Regular status updates at least every 14 days until the issue is resolved
  • Credit in our security hall of fame (if you opt in) when the fix is shipped
  • No legal action against good-faith researchers who follow this policy (see Safe Harbor below)

4. Safe Harbor — What's In Scope

You can test the following without fear of legal action, provided you act in good faith and follow the rules in §6 below:

  • The web app at runonrealms.com and all subdomains
  • The ROR mobile apps on iOS and Android
  • The API at api.runonrealms.com
  • The admin panel (without attempting unauthorized access to real admin accounts)

We commit to:

  • Not pursuing legal action against researchers who follow this policy
  • Working with you to understand and fix the issue quickly
  • Treating your testing activity as authorized under applicable computer crime laws

5. Out of Scope

The following are NOT covered by Safe Harbor and may result in account termination or legal action:

  • Testing against accounts you do not own, or attempting to access other users' private data
  • Denial-of-service (DoS) or volumetric attacks that disrupt service for real users
  • Social engineering of our employees, customers, or vendors
  • Physical attacks on our offices or infrastructure
  • Testing on third-party services we rely on (Razorpay, Stripe, Mapbox, AWS, etc.) — report those to the vendor directly
  • Reports based purely on missing security headers without demonstrated exploitability
  • Self-XSS or other issues requiring victim to perform highly unusual actions
  • Spam, phishing, or any commercial / extortive activity

6. Rules of Engagement

  • Use only your own accounts for testing. Don't access, modify, or delete data belonging to other users.
  • Avoid causing harm. No DoS, no spam, no data destruction, no service disruption.
  • Don't exfiltrate data. If you find a way to access data, stop immediately, document the proof-of-concept with minimal data, and report it.
  • Don't publicly disclose the vulnerability until we've had a reasonable opportunity to fix it (typically 90 days from initial report; we will work with you on the timeline).
  • Don't accept payment for silence. We do not offer monetary bug bounties at this time, but we do offer recognition and our genuine gratitude. We will never ask you to keep a vulnerability secret in exchange for compensation.

7. Severity Examples

SeverityExamplesTarget SLA
CriticalRCE, auth bypass, mass-PII exposure, payment manipulationFix < 24h
HighAccount takeover (single user), stored XSS in admin panel, IDOR exposing private user dataFix < 7 days
MediumReflected XSS, CSRF on sensitive action, info disclosure (non-PII)Fix < 30 days
LowSelf-XSS, clickjacking on non-sensitive pages, verbose error messagesFix < 90 days or accepted risk

8. Contact

Security Disclosure Contact

Mobinsons Ventures Private Limited

CIN: U62011OD2026PTC053747

Email: [email protected]

Subject: Security Disclosure: [brief description]

PGP key: available on request

Run on Realms

Run on Realms — India's Gamified Running Game.
Claim it. Defend it. Own it.

Product
FeaturesRun & Win SeasonJoin WaitlistRefer & EarnBlogFAQ
Legal
Terms of ServicePrivacy PolicyCookie PolicyRefund & CancellationShipping & ReturnsCopyright PolicyDelete Account
Trust & Safety
Community GuidelinesRunner SafetySecurity Disclosure
Connect
Help & SupportEmail UsGrievance OfficerInstagramX / TwitterLinkedInReddit

ROR is a product of Mobinsons Ventures Private Limited (CIN: U62011OD2026PTC053747), registered in India. By using this service you agree to our Terms of Service and Privacy Policy. For grievances, contact our Grievance Officer at [email protected].

© 2026 Mobinsons Ventures Private Limited. All rights reserved. · Built in India 🇮🇳 for runners everywhere