HOSTILE BY DESIGN

Security model

Challenge workloads are treated as untrusted from creation through destruction.

Isolation

One shared Vercel Sandbox MicroVM serves many isolated attack sessions. The router validates the Bearer token and derives a session namespace with HKDF. Outbound networking is denied. No Convex credentials, application secrets or account API keys enter the sandbox.

Credentials

Account API keys and temporary attack tokens are stored as keyed hashes. RankHack Proofs are unique to one arena round and attack session. Only proof verifiers are stored. Replays, stale submissions and cross-session submissions are rejected.

Abuse controls

Convex and the arena router enforce join, heartbeat, body, connection, per-session request, global arena request and proof submission limits. Stale sessions and expired arenas close automatically.

Report a vulnerability

Do not test against production accounts or unrelated targets. Send a concise report with reproduction steps to security@rankhack.lol. We will acknowledge valid reports and coordinate remediation.