SECURITY TESTING AND UNSOLICITED VULNERABILITY REPORTS
Effective September 30, 2026
Ryan has discontinued its public bug bounty program and is no longer accepting unsolicited vulnerability disclosures or security testing proposals.
Ryan does not offer or pay bounties, rewards, fees, or other compensation for unsolicited vulnerability reports, security findings, bug disclosures, or testing activities, regardless of the finding’s severity, novelty, or potential impact.
Any scanning, penetration testing, exploitation, or access to Ryan systems, networks, applications, accounts, or data requires Ryan’s express prior written authorization. Nothing in this notice grants or implies such authorization.
Ryan may review unsolicited security information at its discretion, but submission of information or receipt of a response does not create any obligation to provide compensation, acknowledge the report, engage in further correspondence, investigate or remediate the issue, provide status updates, or provide public recognition.
