Introduction
Welcome to our Bug Bounty Program! We are rigorously working behind the scenes, cleaning up known issues in our software systems, but we are aware that there could be other undiscovered vulnerabilities. As part of our commitment to ensure the safety and privacy of our vehicles and customers, we are extending an invitation to skilled individuals to assist us in identifying these vulnerabilities.
Our worst-case scenarios are:
The scenarios that worry us the most revolve around the safety of our drivers and the integrity of our vehicles. Some of these scenarios include but are not limited to:
Remote control of vehicle systems: Any vulnerability that could allow unauthorized remote control of any vehicle systems. Keep in mind, the vehicles themselves are not part of this Bug Bounty program.
Privacy invasion: Vulnerabilities that could allow unauthorized access to private user data stored in our systems, including but not limited to personal identification information, location data, or payment details.
Disruption of communication: Any bugs that could interrupt communication between the vehicle and the central control system, potentially leaving vehicles isolated or unresponsive to vital updates and commands.
Any useful infrastructure information:
Business Site
Business portal (https://business.rivian.com) is used to support our Fleet customers. This application requires Fleet credentials which a general commercial customer would not have. The primary testing for this domain is the authentication/authorization of the publicly available endpoints.
Basecamp
Basecamp (basecamp.rivian.com) is an externally exposed portal for Rivian partners. We do not provide an option for customers or security researchers to create credentials for authenticated testing. Rather the scope of testing for this domain is authentication bypass.
Feedback
Would you like to help us improve our program or have some feedback to share, please send your anonymous feedback here:
Program feedback link
Please note this form will be checked periodically and should not be used for submission or support queries.