Initial triage
48h
Operational target for first review.
Public Security Program
Responsible disclosure helps us protect users faster. Review scope and policy requirements, then submit findings through a secure workflow.
Initial triage
48h
Operational target for first review.
In-scope assets
N/A
Actively published testing targets.
Hall of Fame
N/A
Researchers publicly recognized.
Program model
Non-bounty
Recognition, badges, and impact visibility.
Step 1
Verify target eligibility and testing constraints before any probing.
Step 2
Provide reproducible steps, impact, and evidence for validation.
Step 3
Receive updates through researcher access verification and thread messaging.
Safe Harbor Highlights
Test only in-scope assets and avoid destructive techniques.
Research in good faith is treated as authorized under this policy.
Report issues through the official submission workflow.
Allow remediation time before any public disclosure.
Legal highlights
Social engineering and physical security testing are prohibited.
DoS, high-volume scanning, and out-of-scope testing are not allowed.
Do not retain sensitive data beyond what is needed to demonstrate impact.
Coordinate disclosure with the security team first.
Confirm your target is in scope before testing.
No. Testing is authorized only for assets explicitly listed in scope.
No. This VDP uses non-bounty recognition through Hall of Fame listings and badges.
You can verify researcher access and continue communication in the report thread portal.
Live leaderboard preview
Recognition list will appear as validated reports are published.
Open Hall of FameSubmit a clear, reproducible report. Include affected asset, impact, and validation steps to speed up triage.