{
  "schema_version": "1.5.0",
  "content_scope": "public_program_policy_summary",
  "counts": {
    "programs": 40,
    "programs_with_scope_context": 25,
    "programs_without_scope_context": 15,
    "programs_with_asset_scope": 40,
    "programs_without_asset_scope": 0,
    "in_scope_entries": 470,
    "out_of_scope_entries": 194
  },
  "notice": "Advertised rewards are not report awards. Asset scope is a dated summary of official policy, not authorization. Read the live official policy before any activity.",
  "rights": "Original summaries CC BY 4.0; linked sources and trademarks retain their own rights.",
  "programs": [
    {
      "schema_version": "1.5.0",
      "id": "1password-bug-bounty",
      "name": "1Password Bug Bounty",
      "operator": "1Password",
      "platform": "HackerOne",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://hackerone.com/1password?type=team",
      "policy_url": "https://hackerone.com/1password?type=team",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": "USD",
        "minimum": null,
        "maximum": 1000000,
        "basis": "advertised_not_individual_award",
        "summary": "Standard advertised tiers span $50–$30,000. The exceptional USD 1,000,000 ceiling applies only to the designated cryptographic challenge’s complete required proof; partial/theoretical claims do not qualify. That challenge now belongs to this same program, without separate invitation.",
        "source_ids": [
          "policy",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "First valid reports receive precedence; related findings may share one bounty. Payment restrictions include sanctions/employer eligibility and guardian handling for minors.",
        "source_ids": [
          "policy",
          "currency"
        ]
      },
      "restrictions": {
        "summary": "Ordinary research is restricted to owned accounts. Privacy violations, destruction, disruption and unauthorized disclosure are prohibited; automation is limited. Local-root scenarios, accepted design limitations and unsupported-impact reports are excluded.",
        "source_ids": [
          "policy",
          "restrictions"
        ]
      },
      "last_verified_at": "2026-10-02T21:22:00Z",
      "limitations": [
        "Current policy and restrictions were read in the browser; static retrieval returned a JavaScript shell.",
        "The normalized maximum is the exceptional challenge ceiling, not the ordinary reward cap. Normalized minimum is null to avoid conflating schedules.",
        "The scope page has stricter ownership language than general permission wording; this summary preserves the stricter restriction.",
        "Policy displayed September 25, 2026 update. Older separate-program challenge descriptions are superseded by current policy."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "1Password bounty policy",
          "url": "https://hackerone.com/1password?type=team",
          "publisher": "1Password / HackerOne",
          "retrieved_at": "2026-10-02T21:22:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "restrictions",
          "title": "1Password program restrictions",
          "url": "https://hackerone.com/1password/policy_scopes",
          "publisher": "1Password / HackerOne",
          "retrieved_at": "2026-10-02T21:22:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "migration",
          "title": "1Password security assessments",
          "url": "https://support.1password.com/security-assessments/",
          "publisher": "1Password",
          "retrieved_at": "2026-10-02T21:22:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "currency",
          "title": "HackerOne vulnerability disclosure guidelines",
          "url": "https://www.hackerone.com/terms/disclosure-guidelines",
          "publisher": "HackerOne",
          "retrieved_at": "2026-10-02T21:22:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published HackerOne structured scope",
          "url": "https://hackerone.com/1password/policy_scopes",
          "publisher": "1Password",
          "retrieved_at": "2026-10-03T14:59:09Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "submission_status": {
        "value": "accepting_reports",
        "summary": "Official support describes a public ongoing program and confirms the December 2024 migration from Bugcrowd to HackerOne.",
        "source_ids": [
          "migration"
        ]
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:59:09Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "http://--your-own-1password-account--.1password.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "<Your own 1Password account> —> Latest stable, beta, or nightly Command Line Interface (CLI)",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "<Your own 1Password account> —> Latest stable, beta, or nightly Browser Extension (Chrome, Brave, Firefox, Edge, and Safari)",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://events.1password.com/api/",
            "asset_type": "API",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          }
        ],
        "out_of_scope": [
          {
            "name": "*.agilebits.com",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "https://support.1password.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "https://www.1password.com/",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "All other domains, subdomains, and 1Password Accounts that are not owned by you, including accounts where you are a user but not the owner, are out of scope.",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          }
        ],
        "limitations": [
          "Published structured-scope rows were captured. Submission eligibility and bounty eligibility differ; program policy text may add restrictions."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "adac-vulnerability-disclosure",
      "name": "ADAC Vulnerability Disclosure Program",
      "operator": "ADAC Group",
      "platform": "Intigriti",
      "program_type": {
        "value": "vulnerability_disclosure",
        "summary": "The policy expressly identifies a disclosure program without monetary bounties.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://app.intigriti.com/programs/adac/adacvulnerabilitydisclosureprogram",
      "policy_url": "https://app.intigriti.com/programs/adac/adacvulnerabilitydisclosureprogram",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "No monetary bounty schedule; currency and numeric bounds are inapplicable and remain null.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Individual researcher-identified accounts and platform membership are required. Platform participation requires adulthood or guardian-approved age 16, and legal/employer eligibility. Internally known findings are duplicates.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Disclosure requires written consent. Social engineering, physical intrusion, denial-of-service and brute force are prohibited. Activity must stop at payment-entry requirements; automation is constrained.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Logged-out policy and login invitation do not independently verify current acceptance.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T03:58:15Z",
      "limitations": [
        "No dedicated announcement archive or complete revision history was established.",
        "Logged-out text review; authenticated eligibility and incorporated documents were not exhaustively checked.",
        "High-level summaries omit inventories and testing instructions. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "ADAC Vulnerability Disclosure Program policy",
          "url": "https://app.intigriti.com/programs/adac/adacvulnerabilitydisclosureprogram",
          "publisher": "ADAC Group / Intigriti",
          "retrieved_at": "2026-10-03T03:56:43Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T03:57:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/adac/adacvulnerabilitydisclosureprogram/detail",
          "publisher": "ADAC Group",
          "retrieved_at": "2026-10-03T14:55:52Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Designated group digital services and hybrid infrastructure, emphasizing confidentiality and integrity of customer, insurance and service-delivery systems.",
        "excluded_summary": "Availability-only issues, generic scanner output, nonconfidential disclosures, unsupported software and specified low-impact application/mobile findings are excluded; compromised-device and physical-access scenarios also face exclusions.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/adac/adacvulnerabilitydisclosureprogram"
        ],
        "verified_at": "2026-10-03T03:58:15Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:55:52Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "all",
            "asset_type": "URL",
            "location": "http://all",
            "group": "No bounty",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "193.30.38.0/24",
            "asset_type": "IP Range",
            "location": null,
            "group": "No bounty",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "193.30.37.0/24",
            "asset_type": "IP Range",
            "location": null,
            "group": "No bounty",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "193.30.36.0/24",
            "asset_type": "IP Range",
            "location": null,
            "group": "No bounty",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "adobe-public-bug-bounty",
      "name": "Adobe Public Bug Bounty",
      "operator": "Adobe",
      "platform": "Intigriti",
      "program_type": {
        "value": "paid_bounty",
        "summary": "Monetary bounties are advertised; awards are discretionary.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://app.intigriti.com/programs/adobe/adobepublic",
      "policy_url": "https://app.intigriti.com/programs/adobe/adobepublic",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Tiers: $150–$15,000, $100–$10,000 and $75–$5,000. Shared-root-cause findings receive one bounty; repeated patterns have a two-report full-bounty cap. Dollar denomination remains unverified, so normalized bounds remain null.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "First reproducible, previously unknown eligible reports qualify. Employee/immediate-family exclusions last 12 months; specified network-access contractors, six. Platform adulthood/guardian-approved age-16 and legal/employer conditions apply.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Product-specific plans override general guidance and constrain environments/accounts. AI-assisted findings need human validation. Privacy violations, disruption, social engineering, unapproved customer environments and premature disclosure are prohibited.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Visible policies and login invitations do not verify acceptance.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T03:41:28Z",
      "limitations": [
        "Updates text retrieval previously failed; no change-log/announcement reviewed.",
        "Test-plan/CVSS attachments remain unreviewed; product conditions are incomplete.",
        "Platform euro settlement does not establish Adobe dollar denomination.",
        "Logged-out review; authenticated eligibility and open/paused status unverified.",
        "High-level context omits asset inventories and testing instructions. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Adobe Public Bug Bounty policy",
          "url": "https://app.intigriti.com/programs/adobe/adobepublic",
          "publisher": "Adobe / Intigriti",
          "retrieved_at": "2026-10-03T03:38:55Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T01:50:12Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/adobe/adobepublic/detail",
          "publisher": "Adobe",
          "retrieved_at": "2026-10-03T14:55:54Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Approved AI, creative/document, commerce, mobile, enterprise, identity and supporting web-service categories, subject to listed products and controlling plans.",
        "excluded_summary": "Unlisted products, third-party code/extensions, licensing bypasses, compromised-device mobile scenarios, unsupported-impact AI claims and low-impact configuration findings are excluded. Product-specific exclusions remain incompletely reviewed.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/adobe/adobepublic"
        ],
        "verified_at": "2026-10-03T03:41:28Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:55:54Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "Acrobat PDF Spaces",
            "asset_type": "AI Model",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Acrobat Create Presentations",
            "asset_type": "AI Model",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Acrobat Create Podcast",
            "asset_type": "AI Model",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Acrobat AI Assistant",
            "asset_type": "AI Model",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Adobe Express AI Assistant",
            "asset_type": "AI Model",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Lightroom AI Features",
            "asset_type": "AI Model",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Adobe Firefly AI Features",
            "asset_type": "AI Model",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Photoshop AI Assistant",
            "asset_type": "AI Model",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Adobe Stock AI Studio",
            "asset_type": "AI Model",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Frame.io iOS Application",
            "asset_type": "iOS",
            "location": "https://apps.apple.com/gb/app/frame-io/id1056295002",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Adobe Fresco (iOS)",
            "asset_type": "iOS",
            "location": "https://apps.apple.com/us/app/adobe-fresco-draw-paint-app/id1458660369",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Adobe Photoshop Express Mobile App (iOS)",
            "asset_type": "iOS",
            "location": "https://apps.apple.com/us/app/photoshop-express-photo-editor/id331975235",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Lightroom Video & Photo Editor (IOS)",
            "asset_type": "iOS",
            "location": "https://apps.apple.com/gb/app/lightroom-video-photo-editor/id878783582",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Lightroom Video & Photo Editor (Android)",
            "asset_type": "Android",
            "location": "https://play.google.com/store/apps/details?id=com.adobe.lrmobile&hl=en_GB",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Adobe Scan Mobile App (iOS)",
            "asset_type": "iOS",
            "location": "https://apps.apple.com/us/app/adobe-scan-pdf-ocr-scanner/id1199564834",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Adobe Scan Mobile App (Android)",
            "asset_type": "Android",
            "location": "https://play.google.com/store/apps/details?id=com.adobe.scan.android&hl=en_GB",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Acrobat Reader Mobile App (iOS)",
            "asset_type": "iOS",
            "location": "https://apps.apple.com/us/app/acrobat-reader-pdf-editor/id469337564",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Acrobat Reader Mobile App (Android)",
            "asset_type": "Android",
            "location": "https://play.google.com/store/apps/details?id=com.adobe.reader&hl=en",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.acrobat.adobe.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "stock.adobe.com",
            "asset_type": "URL",
            "location": "http://stock.adobe.com",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "firefly.adobe.com",
            "asset_type": "URL",
            "location": "http://firefly.adobe.com",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Adobe ColdFusion without ColdFusion Administrator",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "ColdFusion Administrator",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.lightroom.adobe.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "photoshop.adobe.com",
            "asset_type": "URL",
            "location": "http://photoshop.adobe.com",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Adobe Commerce, Adobe Commerce B2B and Magento Open Source",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "account.magento.com",
            "asset_type": "URL",
            "location": "http://account.magento.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "commercemarketplace.adobe.com",
            "asset_type": "URL",
            "location": "http://commercemarketplace.adobe.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "repo.magento.com",
            "asset_type": "URL",
            "location": "http://repo.magento.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "magento.com",
            "asset_type": "URL",
            "location": "http://magento.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "learningmanagerstage4.adobe.com",
            "asset_type": "URL",
            "location": "http://learningmanagerstage4.adobe.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "net.s2stagehance.com",
            "asset_type": "URL",
            "location": "http://net.s2stagehance.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "new.express.adobe.com",
            "asset_type": "URL",
            "location": "http://new.express.adobe.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "portfolio.ccpsx.com",
            "asset_type": "URL",
            "location": "http://portfolio.ccpsx.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "fonts.adobe.com",
            "asset_type": "URL",
            "location": "http://fonts.adobe.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "account.adobe.com",
            "asset_type": "URL",
            "location": "http://account.adobe.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "auth.services.adobe.com",
            "asset_type": "URL",
            "location": "http://auth.services.adobe.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "adobeid-na1.services.adobe.com",
            "asset_type": "URL",
            "location": "http://adobeid-na1.services.adobe.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "ims-na1.adobelogin.com",
            "asset_type": "URL",
            "location": "http://ims-na1.adobelogin.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "federatedid-na1.services.adobe.com",
            "asset_type": "URL",
            "location": "http://federatedid-na1.services.adobe.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope.",
          "The published table repeated ColdFusion Administrator in the same tier; this snapshot deduplicates that identical row."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "apple-security-bounty",
      "name": "Apple Security Bounty",
      "operator": "Apple",
      "platform": "Independent",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "rewards",
          "announcement"
        ]
      },
      "program_url": "https://security.apple.com/bounty/",
      "policy_url": "https://security.apple.com/bounty/guidelines/",
      "announcement_urls": [
        "https://security.apple.com/blog/apple-security-bounty-evolved/"
      ],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Published base maximum $2,000,000; potential above $5,000,000 with applicable bonuses. Awards depend on demonstrated outcome, validation requirements and Apple’s discretion.",
        "source_ids": [
          "rewards",
          "announcement"
        ]
      },
      "eligibility": {
        "summary": "First complete actionable report through Apple’s portal; current-software/configuration requirements apply. Former employees, contractors and interns generally wait 18 months. Sanctions restrictions apply.",
        "source_ids": [
          "policy",
          "terms"
        ]
      },
      "restrictions": {
        "summary": "Preserve confidentiality until Apple’s update and advisory; do not harm others’ data or availability. Apple Pay, non-public systems, third-party services, social engineering and unvalidated reports are excluded.",
        "source_ids": [
          "policy",
          "terms"
        ]
      },
      "last_verified_at": "2026-10-03T03:41:39Z",
      "limitations": [
        "Reviewed pages display dollar signs without an explicit ISO currency code; numeric currency-normalized bounds remain null.",
        "Bonus-qualified ceilings are not guaranteed awards and must not be treated as ordinary base payouts.",
        "No dedicated policy change-log URL was verified.",
        "Only guidelines and terms were refreshed for scope context; reward and announcement evidence retains its earlier retrieval date. Scope summaries are non-exhaustive, omit asset inventories and testing instructions, and grant no authorization."
      ],
      "sources": [
        {
          "id": "program",
          "title": "Apple Security Bounty",
          "url": "https://security.apple.com/bounty/",
          "publisher": "Apple",
          "retrieved_at": "2026-10-02T21:01:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "rewards",
          "title": "Apple bounty categories",
          "url": "https://security.apple.com/bounty/categories/",
          "publisher": "Apple",
          "retrieved_at": "2026-10-02T21:01:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "policy",
          "title": "Apple bounty guidelines",
          "url": "https://security.apple.com/bounty/guidelines/",
          "publisher": "Apple",
          "retrieved_at": "2026-10-03T03:38:36Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "terms",
          "title": "Apple security terms and conditions",
          "url": "https://security.apple.com/terms-and-conditions/",
          "publisher": "Apple",
          "retrieved_at": "2026-10-03T03:39:06Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "announcement",
          "title": "Apple Security Bounty evolved",
          "url": "https://security.apple.com/blog/apple-security-bounty-evolved/",
          "publisher": "Apple",
          "retrieved_at": "2026-10-02T21:01:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Apple Security Bounty guidelines",
          "url": "https://security.apple.com/bounty/guidelines/",
          "publisher": "Apple",
          "retrieved_at": "2026-10-03T15:03:35Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-terms-2026-10-03",
          "title": "Apple Security Bounty terms",
          "url": "https://security.apple.com/terms-and-conditions/",
          "publisher": "Apple",
          "retrieved_at": "2026-10-03T15:03:35Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "submission_status": {
        "value": "unknown",
        "summary": "Official policy reviewed, but a live submission-acceptance indicator was not separately established.",
        "source_ids": []
      },
      "scope_context": {
        "included_summary": "Apple hardware, current operating-system releases including eligible betas, and Apple-owned public-facing services, subject to standard-configuration and report-validation requirements.",
        "excluded_summary": "Apple Pay, non-public-facing systems and third-party products/services are outside coverage. Phishing, social engineering, unauthorized interference with others’ data/property, service disruption affecting others, brute-force qualification attempts, theoretical claims and unvalidated AI reports are excluded. Confidentiality continues through the update and security advisory; repeated ineligible submissions can suspend or end participation.",
        "source_ids": [
          "policy",
          "terms"
        ],
        "policy_urls": [
          "https://security.apple.com/bounty/guidelines/",
          "https://security.apple.com/terms-and-conditions/"
        ],
        "verified_at": "2026-10-03T03:41:39Z"
      },
      "asset_scope": {
        "capture_status": "policy_defined",
        "collection_method": "official_policy_page",
        "verified_at": "2026-10-03T15:03:35Z",
        "source_ids": [
          "assets-scope-2026-10-03",
          "assets-terms-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "iOS",
            "asset_type": "operating_system",
            "location": null,
            "group": "Current public release, including eligible beta",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "iPadOS",
            "asset_type": "operating_system",
            "location": null,
            "group": "Current public release, including eligible beta",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "macOS",
            "asset_type": "operating_system",
            "location": null,
            "group": "Current public release, including eligible beta",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "tvOS",
            "asset_type": "operating_system",
            "location": null,
            "group": "Current public release, including eligible beta",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "visionOS",
            "asset_type": "operating_system",
            "location": null,
            "group": "Current public release, including eligible beta",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "watchOS",
            "asset_type": "operating_system",
            "location": null,
            "group": "Current public release, including eligible beta",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Publicly available Apple hardware",
            "asset_type": "hardware",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Standard configuration and applicable Apple-designed components."
          },
          {
            "name": "Apple-owned public-facing web servers and services",
            "asset_type": "policy_category",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "No finite hostname inventory is published in these terms."
          }
        ],
        "out_of_scope": [
          {
            "name": "Apple Pay",
            "asset_type": "product",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-terms-2026-10-03"
            ]
          },
          {
            "name": "Non-public-facing Apple systems",
            "asset_type": "policy_category",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-terms-2026-10-03"
            ]
          },
          {
            "name": "Third-party products and services",
            "asset_type": "policy_category",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-terms-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Apple defines broad product and service categories rather than a finite host inventory; current release, configuration and reporting criteria apply."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "arc-circle-bug-bounty",
      "name": "Arc Bug Bounty",
      "operator": "Circle Internet Contract Services, LLC",
      "platform": "HackerOne",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://hackerone.com/arc-bbp?type=team",
      "policy_url": "https://hackerone.com/arc-bbp?type=team",
      "announcement_urls": [
        "https://hackerone.com/arc-bbp/updates"
      ],
      "change_log_url": "https://hackerone.com/arc-bbp/updates",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "last_verified_at": "2026-10-03T01:51:44Z",
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Paid bounty. Chain/protocol Tier A: Low up to $5,000 (table starts at $50), Medium $5,000–$10,000, High $10,000–$20,000, Critical $20,000–$200,000. A separate extreme-impact category advertises up to $1,000,000. Product/web Tier B: Low $50–$400, Medium $400–$800, High $800–$3,000, Critical $3,000–$10,000. All payment decisions remain discretionary; neither ceiling is an actual award.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Participants must be at least 18, comply with applicable law and sanctions restrictions, and submit in English. Employees of Circle or affiliates and their immediate families are excluded. The first reproducible duplicate report takes precedence; one root cause receives one award. Reporting licenses the submission to Circle and permits compliance-related sharing of tax-form personal information.",
        "source_ids": [
          "policy"
        ]
      },
      "restrictions": {
        "summary": "Mainnet testing is prohibited; permitted research is confined to designated test or local environments. Use owned or explicitly authorized accounts/wallets, avoid other users’ data and financial loss, and do not disrupt services or use social engineering. Source-manipulation, unit-test, low-impact best-practice and unsupported library findings are excluded. Disclosure, including resolved findings, requires written consent. Safe harbor is conditional and terms may change without notice.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "A public bounty policy and submission link were visible without a pause notice. Neither current acceptance nor individual eligibility was explicitly established or tested; activity statistics alone are not treated as confirmation.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "This Arc is Circle’s financial-platform program, not a browser product. Policy displays September 16, 2026; reward table displays September 14, 2026.",
        "Only dollar notation was established, so ISO currency and normalized numerical bounds remain null. The exceptional $1,000,000 category is separate from the ordinary $200,000 critical ceiling.",
        "The reviewed updates page explicitly displayed no updates. Linked policy and reward revision archives and authenticated submission flow were not reviewed.",
        "The policy both lists examples of low-tier rewards and excludes similar low-impact categories elsewhere. Eligibility depends on concrete impact and the full live terms; this summary does not resolve that tension.",
        "Asset inventories and operational instructions are intentionally omitted. No account was created, report submitted or target tested; this record grants no testing permission."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Arc | Bounty Policy | HackerOne",
          "url": "https://hackerone.com/arc-bbp?type=team",
          "publisher": "Circle / HackerOne",
          "retrieved_at": "2026-10-03T01:51:06Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "updates",
          "title": "Arc public program updates",
          "url": "https://hackerone.com/arc-bbp/updates",
          "publisher": "Circle / HackerOne",
          "retrieved_at": "2026-10-03T01:51:44Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published HackerOne structured scope",
          "url": "https://hackerone.com/arc-bbp/policy_scopes",
          "publisher": "Circle Internet Contract Services, LLC",
          "retrieved_at": "2026-10-03T14:59:10Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:59:10Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "*.arc.io",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "rpc.testnet.arc.network",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "rpc.drpc.testnet.arc.network",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/circlefin/malachite",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/circlefin/arc-node",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/circlefin/arc-remote-signer",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          }
        ],
        "out_of_scope": [
          {
            "name": "community.arc.io",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "explorer.arc.io",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "help.arc.io",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          }
        ],
        "limitations": [
          "Published structured-scope rows were captured. Submission eligibility and bounty eligibility differ; program policy text may add restrictions."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "atlassian-bug-bounty",
      "name": "Atlassian Bug Bounty",
      "operator": "Atlassian",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy",
          "updates"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/atlassian",
      "policy_url": "https://bugcrowd.com/engagements/atlassian",
      "announcement_urls": [
        "https://bugcrowd.com/engagements/atlassian/announcements"
      ],
      "change_log_url": "https://bugcrowd.com/engagements/atlassian/announcements",
      "rewards": {
        "currency": "USD",
        "minimum": 100,
        "maximum": 12000,
        "basis": "advertised_not_individual_award",
        "summary": "Tier-dependent advertised awards span $100–$12,000. Product/severity schedules differ and awards are discretionary. April 16, 2026 updates raised top-tier P1/P2 awards and reduced P3/P4 awards.",
        "source_ids": [
          "policy",
          "currency",
          "updates"
        ]
      },
      "eligibility": {
        "summary": "First valid previously unknown report for cash eligibility. Designated researcher accounts, owned instances and latest applicable product versions are required.",
        "source_ids": [
          "policy",
          "eligibility"
        ]
      },
      "restrictions": {
        "summary": "No customer data, others’ repositories, credential validation, automated scanners, social engineering, physical attacks or post-exploitation pivoting. Cloud denial-of-service and low-impact categories are excluded. Plain-text reports and permission before disclosure are required; safe harbor is conditional.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-02T21:22:00Z",
      "limitations": [
        "Full policy and announcement reviewed in the cloud browser; web text retrieval supplied only a login shell.",
        "Program charts use dollar signs; USD normalization relies on official Bugcrowd accounting documentation describing reward transactions, not an explicit ISO code in this brief.",
        "Policy displayed June 12, 2026 update. Summaries omit asset lists and are not exhaustive."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Atlassian program brief",
          "url": "https://bugcrowd.com/engagements/atlassian",
          "publisher": "Atlassian / Bugcrowd",
          "retrieved_at": "2026-10-02T21:22:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "updates",
          "title": "Atlassian program announcements",
          "url": "https://bugcrowd.com/engagements/atlassian/announcements",
          "publisher": "Atlassian / Bugcrowd",
          "retrieved_at": "2026-10-02T21:22:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd fund management overview",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-02T21:22:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "eligibility",
          "title": "Getting rewarded",
          "url": "https://docs.bugcrowd.com/researchers/receiving-rewards/getting-rewarded/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-02T21:22:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/atlassian/changelog/c31ec9fd-9fff-4aa1-9b4e-aa9929f1086a.json",
          "publisher": "Atlassian",
          "retrieved_at": "2026-10-03T14:55:55Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "submission_status": {
        "value": "accepting_reports",
        "summary": "Official page displayed In progress and an ongoing period; eligibility and current restrictions still apply.",
        "source_ids": [
          "policy"
        ]
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:55:55Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "Atlassian Guard Standard and Premium (https://admin.atlassian.com/atlassian-guard)",
            "asset_type": "website",
            "location": "https://admin.atlassian.com/atlassian-guard",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Atlassian Admin (https://admin.atlassian.com/)",
            "asset_type": "website",
            "location": "https://admin.atlassian.com/",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Atlassian Identity (https://id.atlassian.com/login)",
            "asset_type": "website",
            "location": "https://id.atlassian.com/login",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Atlassian Start (https://start.atlassian.com)",
            "asset_type": "website",
            "location": "https://start.atlassian.com",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Bitbucket Cloud including Bitbucket Pipelines (https://bitbucket.org)",
            "asset_type": "website",
            "location": "https://bitbucket.org",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Confluence Cloud (bugbounty-test-<bugcrowd-name>.atlassian.net/wiki)",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/confluence",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Confluence Cloud Premium (bugbounty-test-<bugcrowd-name>.atlassian.net/wiki)",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/confluence/premium",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Confluence Cloud Mobile App for Android",
            "asset_type": "android",
            "location": "https://play.google.com/store/apps/details?id=com.atlassian.android.confluence.core&hl=en_US&gl=US",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Confluence Cloud Mobile App for iOS",
            "asset_type": "ios",
            "location": "https://apps.apple.com/us/app/confluence-cloud/id1006971684",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Cloud Mobile App for Android",
            "asset_type": "android",
            "location": "https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&hl=en_US&gl=US",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Cloud Mobile App for iOS",
            "asset_type": "ios",
            "location": "https://apps.apple.com/us/app/jira-cloud-by-atlassian/id1006972087",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Service Management Cloud (bugbounty-test-<bugcrowd-name>.atlassian.net)",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/jira/service-management",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Software Cloud (bugbounty-test-<bugcrowd-name>.atlassian.net)",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/jira",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Work Management Cloud formerly Jira Core (bugbounty-test-<bugcrowd-name>.atlassian.net)",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/jira/work-management",
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Any associated *.atlassian.com or *.atl-paas.net domain that can be exploited DIRECTLY from the *.atlassian.net instance",
            "asset_type": "other",
            "location": null,
            "group": "Tier 1 ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Rovo",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/rovo",
            "group": "Rovo, Rovo Dev and other AI Features",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Rovo Dev CLI",
            "asset_type": "other",
            "location": "https://support.atlassian.com/rovo/docs/use-rovo-dev-cli/",
            "group": "Rovo, Rovo Dev and other AI Features",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Other Rovo Dev",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/rovo-dev",
            "group": "Rovo, Rovo Dev and other AI Features",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Atlassian MCP Server",
            "asset_type": "other",
            "location": "https://mcp.atlassian.com",
            "group": "Rovo, Rovo Dev and other AI Features",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Atlassian Marketplace (https://marketplace.atlassian.com)",
            "asset_type": "website",
            "location": "https://marketplace.atlassian.com",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Atlassian Atlas",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/atlas",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.atlastunnel.com",
            "asset_type": "website",
            "location": "https://*.atlastunnel.com",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Any other *.atlassian.com or *.atl-paas.net domain that cannot be exploited directly from a *.atlassian.net instance",
            "asset_type": "website",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.loom.com",
            "asset_type": "website",
            "location": "https://www.loom.com/",
            "group": "Atlassian Loom",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Loom Desktop App (Windows)",
            "asset_type": "website",
            "location": "https://www.loom.com/download",
            "group": "Atlassian Loom",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Loom Desktop App (macOS)",
            "asset_type": "website",
            "location": "https://www.loom.com/download",
            "group": "Atlassian Loom",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Loom for Android",
            "asset_type": "android",
            "location": "https://play.google.com/store/apps/details?id=com.loom.android&hl=en_US&pli=1",
            "group": "Atlassian Loom",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Loom for iOS",
            "asset_type": "ios",
            "location": "https://apps.apple.com/us/app/loom-screen-recorder/id1474480829",
            "group": "Atlassian Loom",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Loom Chrome Extension",
            "asset_type": "other",
            "location": "https://chromewebstore.google.com/detail/loom-%E2%80%93-screen-recorder-sc/liecbddmkiiihnedobmlmillhodjkdmb?hl=en-US&pli=1",
            "group": "Atlassian Loom",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Atlassian Compass",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/compass",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Bamboo",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/bamboo",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Bitbucket Data Center",
            "asset_type": "website",
            "location": "https://www.atlassian.com/enterprise/data-center/bitbucket",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Confluence Companion App for macOS and Windows",
            "asset_type": "other",
            "location": "https://confluence.atlassian.com/doc/install-atlassian-companion-992678880.html",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Confluence Data Center Mobile App for Android",
            "asset_type": "android",
            "location": "https://play.google.com/store/apps/details?id=com.atlassian.confluence.server",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Confluence Data Center Mobile App for iOS",
            "asset_type": "ios",
            "location": "https://apps.apple.com/us/app/confluence-server/id1288365159",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Crucible",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/crucible",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Confluence Data Center",
            "asset_type": "other",
            "location": "https://www.atlassian.com/enterprise/data-center/confluence",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Crowd",
            "asset_type": "website",
            "location": "https://www.atlassian.com/enterprise/data-center/crowd",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "FishEye",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/fisheye",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Core Data Center",
            "asset_type": "website",
            "location": "https://www.atlassian.com/enterprise/data-center/jira",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Data Center Mobile App for Android",
            "asset_type": "android",
            "location": "https://play.google.com/store/apps/details?id=com.atlassian.jira.server&hl=en_US&gl=US",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Data Center Mobile App for iOS",
            "asset_type": "ios",
            "location": "https://apps.apple.com/us/app/jira-server/id1405353949",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Product Discovery",
            "asset_type": "website",
            "location": "https://www.atlassian.com/software/jira/product-discovery",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Service Management Data Center",
            "asset_type": "website",
            "location": "https://www.atlassian.com/enterprise/data-center/jira/service-management",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Jira Software Data Center",
            "asset_type": "website",
            "location": "https://www.atlassian.com/enterprise/data-center/jira",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Sourcetree for macOS and Windows (https://www.sourcetreeapp.com/)",
            "asset_type": "other",
            "location": "https://www.sourcetreeapp.com/",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Other - (all other Atlassian targets)",
            "asset_type": "other",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Forge Platform",
            "asset_type": "other",
            "location": null,
            "group": "Atlassian Forge",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "GraphQL API (bugbounty-test-<bugcrowd-name>.atlassian.net/gateway/api/graphql)",
            "asset_type": "api",
            "location": null,
            "group": "Atlassian Forge",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://www.npmjs.com/package/@forge/cli",
            "asset_type": "other",
            "location": "https://www.npmjs.com/package/@forge/cli\t",
            "group": "Atlassian Forge",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "Any internal or development services.",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "First and third party apps and plugins from the marketplace are excluded from this bounty but may be in scope for https://bugcrowd.com/atlassianapps",
            "asset_type": "website",
            "location": "https://bugcrowd.com/atlassianapps",
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "shop.atlassian.com",
            "asset_type": "website",
            "location": "https://shop.atlassian.com",
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "bytebucket.org",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.bitbucket.io",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://blog.bitbucket.org",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "HipChat (inc. HipChat Data Center, HipChat Desktop, HipChat Mobile)",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Stride (inc. Stride Video, Stride Desktop, Stride Mobile)",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "support.atlassian.com",
            "asset_type": "website",
            "location": "https://support.atlassian.com",
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Any customer instance. Do not test customer instances or affect customer data. Customer cloud instances may be in the form of <customer>.atlassian.net or <customer>.jira.com. Test only your own instances.",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Any repository that you are not an owner of - do not impact Atlassian customers in any way.",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "support.loom.com",
            "asset_type": "website",
            "location": "https://support.loom.com",
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "info.loom.com",
            "asset_type": "website",
            "location": "https://info.loom.com/",
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "curl-vulnerability-disclosure",
      "name": "curl Vulnerability Disclosure",
      "operator": "curl project",
      "platform": "HackerOne",
      "program_url": "https://hackerone.com/curl?type=team",
      "policy_url": "https://hackerone.com/curl?type=team",
      "announcement_urls": [
        "https://curl.se/mail/lib-2026-01/0030.html",
        "https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/"
      ],
      "change_log_url": "https://hackerone.com/curl/updates",
      "last_verified_at": "2026-10-03T03:41:39Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "program_type": {
        "value": "vulnerability_disclosure",
        "summary": "The current official policy explicitly excludes monetary rewards.",
        "source_ids": [
          "policy"
        ]
      },
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Current reports receive recognition rather than money. The former paid bounty ended January 31, 2026; that historical closure does not establish closure of disclosure intake.",
        "source_ids": [
          "policy",
          "closure"
        ]
      },
      "eligibility": {
        "summary": "Previously unreported, unpublished security issues in the latest released version qualify for review. AI assistance must be disclosed and its claims independently checked. Experimental features and most infrastructure issues are excluded.",
        "source_ids": [
          "policy"
        ]
      },
      "restrictions": {
        "summary": "Preserve privacy, data integrity and availability; no disruption, spam or social engineering. Allow remediation before disclosure. Reports may become public after handling and sensitive-content review. Safe harbor is conditional.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "A submission link is visible, but current acceptance was not independently established. Sources disagree on the reporting channel; no current migration or complete intake closure is asserted.",
        "source_ids": [
          "policy",
          "disclosure",
          "closure"
        ]
      },
      "official_program_links": [
        {
          "url": "https://curl.se/dev/vuln-disclosure.html",
          "source_ids": [
            "disclosure"
          ],
          "note": "Project disclosure policy linked to the same HackerOne program."
        },
        {
          "url": "https://curl.se/docs/bugbounty.html",
          "source_ids": [
            "redirect"
          ],
          "note": "Former bounty URL redirected to the project disclosure policy during this review."
        }
      ],
      "limitations": [
        "The HackerOne policy displays May 13, 2026. Its updates page contains no updates; revision archives were not reviewed.",
        "The January 26 announcement directed reports to GitHub or email. The current project policy instead directs them to HackerOne and rejects email reporting; browser review confirmed that discrepancy.",
        "No age or residency rule was established. No account, submission or target interaction occurred. Full live terms prevail; this summary grants no authorization.",
        "Only the project disclosure policy was refreshed for scope context; platform policy, updates and closure notices retain their earlier retrieval dates. No overall revision date or exhaustive exclusion coverage is asserted."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "curl public vulnerability-disclosure policy",
          "url": "https://hackerone.com/curl?type=team",
          "publisher": "curl project / HackerOne",
          "retrieved_at": "2026-10-03T02:31:44Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "disclosure",
          "title": "curl vulnerability disclosure policy",
          "url": "https://curl.se/dev/vuln-disclosure.html",
          "publisher": "curl project",
          "retrieved_at": "2026-10-03T03:39:31Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "closure-notice",
          "title": "The curl bug-bounty ends on January 31, 2026",
          "url": "https://curl.se/mail/lib-2026-01/0030.html",
          "publisher": "curl project / Daniel Stenberg",
          "retrieved_at": "2026-10-03T02:31:44Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "closure",
          "title": "The end of the curl bug-bounty",
          "url": "https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/",
          "publisher": "Daniel Stenberg, curl maintainer",
          "retrieved_at": "2026-10-03T02:31:44Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "updates",
          "title": "curl program updates",
          "url": "https://hackerone.com/curl/updates",
          "publisher": "curl project / HackerOne",
          "retrieved_at": "2026-10-03T02:31:44Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "redirect",
          "title": "Former curl bug bounty page, redirected to disclosure policy",
          "url": "https://curl.se/docs/bugbounty.html",
          "publisher": "curl project",
          "retrieved_at": "2026-10-03T02:31:44Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published HackerOne structured scope",
          "url": "https://hackerone.com/curl/policy_scopes",
          "publisher": "curl project",
          "retrieved_at": "2026-10-03T14:59:11Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "scope_context": {
        "included_summary": "Security defects in released transfer-client and library code, evaluated for practical confidentiality, integrity or availability impact.",
        "excluded_summary": "Unreleased, off-by-default experimental, debug-only and test-suite code is excluded. Small leaks, ordinary stalled transfers, terminating busy loops, API misuse, expected parser differences and crash-only cases generally are not security issues; material impact can change some assessments. Command-line deception, expected terminal output and legacy-dependency-only cases are also excluded. The official list is explicitly incomplete.",
        "source_ids": [
          "disclosure"
        ],
        "policy_urls": [
          "https://curl.se/dev/vuln-disclosure.html"
        ],
        "verified_at": "2026-10-03T03:41:39Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:59:11Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "https://github.com/curl/curl",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published structured-scope rows were captured. Submission eligibility and bounty eligibility differ; program policy text may add restrictions."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "dashlane-vulnerability-disclosure",
      "name": "Dashlane Vulnerability Disclosure Program",
      "operator": "Dashlane",
      "platform": "Intigriti",
      "program_type": {
        "value": "vulnerability_disclosure",
        "summary": "Explicit unpaid public VDP; its private paid program is separate.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://app.intigriti.com/programs/dashlane/dashlanevulnerabilitydisclosureprogram",
      "policy_url": "https://app.intigriti.com/programs/dashlane/dashlanevulnerabilitydisclosureprogram",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Currency/bounds are inapplicable. Generic reward wording and possible private-program invitations do not promise cash.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Intigriti accounts and researcher identification are required. Reports need clear evidence, individual findings and exclusive coordinated submission. Platform adulthood/guardian-approved age-16 and legal/employer conditions apply.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Only owned/authorized accounts. Prohibited: disruption, high-volume automation, automated account creation, social engineering, user-data interference, physical attacks and public video hosting.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Visible policies and login invitations do not verify acceptance.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T03:41:28Z",
      "limitations": [
        "FAQ accepts reports on other Dashlane-controlled assets; broader reporting does not expand listed-only testing authorization.",
        "No dedicated announcement/change-log or expanded safe-harbor text verified.",
        "Logged-out review; authenticated eligibility and open/paused status unverified.",
        "High-level context omits asset inventories and testing instructions. Live terms prevail; this record grants no authorization.",
        "Historical average $185/total $925 payouts neither establish a current schedule nor an individual award; explicit no-bounty terms prevail."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Dashlane Vulnerability Disclosure Program policy",
          "url": "https://app.intigriti.com/programs/dashlane/dashlanevulnerabilitydisclosureprogram",
          "publisher": "Dashlane / Intigriti",
          "retrieved_at": "2026-10-03T03:38:55Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T01:50:12Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/dashlane/dashlanevulnerabilitydisclosureprogram/detail",
          "publisher": "Dashlane",
          "retrieved_at": "2026-10-03T14:55:58Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Approved credential-security web services, APIs, browser extensions, autofill/autologin, mobile applications, business/enterprise features, shared-credential workflows and federated authentication, within Dashlane ownership/control and listed testing boundaries.",
        "excluded_summary": "Unlisted active testing, the company blog and unconfirmed third-party services; known sharing limitations, enumeration, unsupported/compromised-device scenarios and best-practice-only claims lacking security impact.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/dashlane/dashlanevulnerabilitydisclosureprogram"
        ],
        "verified_at": "2026-10-03T03:41:28Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:55:58Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "*.dashlane.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Dashlane Mobile Applications",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Autofill and Autologin Functionality",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Dashlane Browser Extensions",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Dashlane Business and Enterprise Features",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Out of Scope",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "dropbox-bug-bounty",
      "name": "Dropbox Bug Bounty",
      "operator": "Dropbox",
      "platform": "Intigriti",
      "program_url": "https://app.intigriti.com/programs/dropbox/dropbox",
      "policy_url": "https://app.intigriti.com/programs/dropbox/dropbox",
      "announcement_urls": [
        "https://app.intigriti.com/programs/dropbox/dropbox/updates"
      ],
      "change_log_url": "https://app.intigriti.com/programs/dropbox/dropbox/updates",
      "last_verified_at": "2026-10-03T03:20:30Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Displayed tiers span $100–$15,000, $100–$10,000 and $100–$7,500. Dollar denomination is unverified; normalized amounts remain null. A discretionary $25 delayed-validation bonus is advertised. Business-only issues may receive a low-severity reward if fixed. These are guidelines, not awards.",
        "source_ids": [
          "policy",
          "updates"
        ]
      },
      "eligibility": {
        "summary": "An Intigriti account, first reporting, demonstrable impact and privacy compliance are required. Duplicate root causes generally receive one reward; alpha/beta findings may pay less. Sanctions apply. Platform terms require adulthood or age 16 with guardian permission, company validation and identity checks.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Use owned test accounts; do not access other users’ private data. No disruption, social engineering, physical intrusion or brute force. Scanner-only reports, unlisted properties and planned-deprecation products are excluded. Public disclosure requires written permission after report closure.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "The public page describes account-based submission but has no explicit current open/paused label. Availability is not inferred from recent activity.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "The updates page includes a November 24, 2025 scope-policy clarification. It is an announcements/changes index, not an exhaustive version history or full-policy revision date.",
        "Platform terms default payments to euros unless otherwise agreed; that does not establish the denomination of the displayed dollar amounts.",
        "The page labels safe harbor as applied, but expanded program-specific terms and authenticated eligibility were not inspected.",
        "Public policy review only. Asset inventories and operational instructions are omitted. Live terms prevail; this summary grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Dropbox Bug Bounty public policy",
          "url": "https://app.intigriti.com/programs/dropbox/dropbox",
          "publisher": "Dropbox / Intigriti",
          "retrieved_at": "2026-10-03T03:20:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "updates",
          "title": "Dropbox Bug Bounty official updates",
          "url": "https://app.intigriti.com/programs/dropbox/dropbox/updates",
          "publisher": "Dropbox / Intigriti",
          "retrieved_at": "2026-10-03T02:14:45Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T02:12:34Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/dropbox/dropbox/detail",
          "publisher": "Dropbox",
          "retrieved_at": "2026-10-03T14:55:58Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "program_type": {
        "value": "paid_bounty",
        "summary": "The official policy advertises monetary bounties for eligible reports.",
        "source_ids": [
          "policy"
        ]
      },
      "scope_context": {
        "included_summary": "Selected storage, signing, fax, document-sharing and productivity products include specified web, API, desktop and mobile components.",
        "excluded_summary": "Excluded categories include deprecated products, third-party integrations, password-management and capture products, and Paper mobile clients; web and mobile coverage differs.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/dropbox/dropbox"
        ],
        "verified_at": "2026-10-03T03:20:30Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:55:58Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "Dropbox.com",
            "asset_type": "URL",
            "location": "http://Dropbox.com",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "sign.dropbox.com",
            "asset_type": "URL",
            "location": "http://sign.dropbox.com",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "HelloSign.com",
            "asset_type": "URL",
            "location": "http://HelloSign.com",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "dash.ai",
            "asset_type": "URL",
            "location": "http://dash.ai",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "dash.dropbox.com",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "api.dropbox.com",
            "asset_type": "URL",
            "location": "http://api.dropbox.com",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Dropbox Desktop Application",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "327630330",
            "asset_type": "iOS",
            "location": "https://apps.apple.com/app/327630330",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "6450553960",
            "asset_type": "iOS",
            "location": "https://apps.apple.com/app/6450553960",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "1080074001",
            "asset_type": "iOS",
            "location": "https://apps.apple.com/app/1080074001",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "com.dropbox.dash",
            "asset_type": "Android",
            "location": "https://play.google.com/store/apps/details?id=com.dropbox.dash",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "com.dropbox.android",
            "asset_type": "Android",
            "location": "https://play.google.com/store/apps/details?id=com.dropbox.android",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "HelloFax.com",
            "asset_type": "URL",
            "location": "http://HelloFax.com",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "docsend.com",
            "asset_type": "URL",
            "location": "http://docsend.com",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "app.Reclaim.ai",
            "asset_type": "URL",
            "location": "http://app.Reclaim.ai",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "dropbox.com/paper",
            "asset_type": "URL",
            "location": "http://dropbox.com/paper",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.dropbox.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.dropboxer.net",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.dropboxforum.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.dropboxpartners.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.hellofax.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.docsend.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.reclaim.ai",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.helloworks.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.hellosign.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.dash.ai",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "community.dropbox.com",
            "asset_type": "URL",
            "location": "http://community.dropbox.com",
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "replay.dropbox.com",
            "asset_type": "URL",
            "location": "http://replay.dropbox.com",
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Boxcryptor",
            "asset_type": "Other",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Formswift",
            "asset_type": "Other",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Dropbox Passwords",
            "asset_type": "Other",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Dropbox Capture Windows Desktop App",
            "asset_type": "Other",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Dropbox Capture macOS Desktop App",
            "asset_type": "Other",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "com.dropbox.paper",
            "asset_type": "Android",
            "location": "https://play.google.com/store/apps/details?id=com.dropbox.paper",
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "1126623662",
            "asset_type": "iOS",
            "location": "https://apps.apple.com/app/1126623662",
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "platform": "Intigriti",
      "program_type": {
        "value": "vulnerability_disclosure",
        "summary": "The policy explicitly describes a disclosure program without monetary bounties.",
        "source_ids": [
          "policy"
        ]
      },
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "No monetary bounty schedule; currency and numeric bounds remain null.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Logged-out policy and login invitation do not independently establish current intake status.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T04:29:23Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "id": "dutch-lottery-vulnerability-disclosure",
      "name": "Dutch Lottery Vulnerability Disclosure Program",
      "operator": "Nederlandse Loterij",
      "program_url": "https://app.intigriti.com/programs/nederlandseloterij/dutchlotteryvdp",
      "policy_url": "https://app.intigriti.com/programs/nederlandseloterij/dutchlotteryvdp",
      "eligibility": {
        "summary": "Platform membership and researcher-identified registration are required. Application self-registration is limited to Dutch residents and citizens. Platform eligibility requires age 18, or 16 with guardian permission, plus legal and employer authorization.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Disclosure requires written consent. Disruption, social engineering, physical intrusion and brute force are prohibited; internally known findings count as duplicates.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "The linked scope attachment was deliberately not collected; coverage is therefore incomplete.",
        "No announcement archive or complete revision history was established. Expanded safe-harbor terms and other incorporated documents remain unreviewed.",
        "Logged-out review; summaries omit inventories and procedures. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Dutch Lottery Vulnerability Disclosure Program policy",
          "url": "https://app.intigriti.com/programs/nederlandseloterij/dutchlotteryvdp",
          "publisher": "Nederlandse Loterij / Intigriti",
          "retrieved_at": "2026-10-03T04:28:45Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T04:29:02Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/nederlandseloterij/dutchlotteryvdp/detail",
          "publisher": "Nederlandse Loterij",
          "retrieved_at": "2026-10-03T14:56:01Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "scope_context": {
        "included_summary": "Designated lottery-related digital services, emphasizing draw and prize integrity, player accounts, customer confidentiality and financial-abuse prevention.",
        "excluded_summary": "Low-impact configuration findings, unsupported-impact claims, unsupported software and scenarios requiring compromised devices, physical access or interception are excluded.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/nederlandseloterij/dutchlotteryvdp"
        ],
        "verified_at": "2026-10-03T04:29:23Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:01Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "www.staatsloterij.nederlandseloterij.nl",
            "asset_type": "URL",
            "location": "http://www.staatsloterij.nederlandseloterij.nl",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.krasloten.nederlandseloterij.nl",
            "asset_type": "URL",
            "location": "http://www.krasloten.nederlandseloterij.nl",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.eurojackpot.nederlandseloterij.nl",
            "asset_type": "URL",
            "location": "http://www.eurojackpot.nederlandseloterij.nl",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.luckyday.nederlandseloterij.nl",
            "asset_type": "URL",
            "location": "http://www.luckyday.nederlandseloterij.nl",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.lotto.nederlandseloterij.nl",
            "asset_type": "URL",
            "location": "http://www.lotto.nederlandseloterij.nl",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.miljoenenspel.nederlandseloterij.nl",
            "asset_type": "URL",
            "location": "http://www.miljoenenspel.nederlandseloterij.nl",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.nederlandseloterij.nl",
            "asset_type": "URL",
            "location": "http://www.nederlandseloterij.nl",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.toto.nl",
            "asset_type": "URL",
            "location": "http://www.toto.nl",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "See the CSV file attached in the In-scope section for a full list of assets in scope",
            "asset_type": "Other",
            "location": null,
            "group": "No bounty",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "exoscale-bug-bounty",
      "name": "Exoscale Bug Bounty",
      "operator": "Exoscale / Akenes SA",
      "platform": "Intigriti",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The policy advertises monetary bounties in two coverage tiers.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://app.intigriti.com/programs/exoscale/excoscalebugbounty",
      "policy_url": "https://app.intigriti.com/programs/exoscale/excoscalebugbounty",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": "EUR",
        "minimum": 50,
        "maximum": 5000,
        "basis": "advertised_not_individual_award",
        "summary": "Tier 2: EUR 50–5,000; Tier 3: EUR 50–2,000. Shared causes yield one bounty. A discretionary EUR 25 delayed-validation bonus is excluded from these bounds.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Reproducible findings and researcher-identified accounts are required. Platform first-valid-report, identity-check, adulthood or guardian-approved age-16, and legal/employer eligibility requirements apply.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Protect customer privacy, integrity and availability. Social engineering and disruption are prohibited; automation and researcher identification are constrained. Disclosure requires written consent.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Logged-out policy and login invitation do not independently verify current acceptance.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T03:58:15Z",
      "limitations": [
        "No dedicated program announcement archive or complete revision history was established.",
        "Logged-out text review; authenticated eligibility and incorporated documents were not exhaustively checked.",
        "High-level summaries omit inventories and testing instructions. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Exoscale Bug Bounty policy",
          "url": "https://app.intigriti.com/programs/exoscale/excoscalebugbounty",
          "publisher": "Exoscale / Akenes SA / Intigriti",
          "retrieved_at": "2026-10-03T03:57:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T03:57:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/exoscale/excoscalebugbounty/detail",
          "publisher": "Exoscale / Akenes SA",
          "retrieved_at": "2026-10-03T14:56:02Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Designated cloud compute, storage, networking, identity and database services, plus supporting web properties. Partner-side database faults have no guaranteed bounty.",
        "excluded_summary": "Customer infrastructure, unlisted properties, content-delivery/private-connectivity and marketplace services, known quota issues, issues causing only inconsequential losses below USD 500 and specified low-impact categories are excluded.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/exoscale/excoscalebugbounty"
        ],
        "verified_at": "2026-10-03T03:58:15Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:02Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "https://portal.exoscale.com/",
            "asset_type": "URL",
            "location": "https://portal.exoscale.com/",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://api-*exoscale.com/v2",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://sos-*.exo.io",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://sks-*.exo.io",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.internal.exoscale.ch",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://www.exoscale.com/",
            "asset_type": "URL",
            "location": "https://www.exoscale.com/",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://community.exoscale.com/",
            "asset_type": "URL",
            "location": "https://community.exoscale.com/",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "https://changelog.exoscale.com/",
            "asset_type": "URL",
            "location": "https://changelog.exoscale.com/",
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://exoscalestatus.com/",
            "asset_type": "URL",
            "location": "https://exoscalestatus.com/",
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://academy.exoscale.com/",
            "asset_type": "URL",
            "location": "https://academy.exoscale.com/",
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://jobs.exoscale.com/",
            "asset_type": "URL",
            "location": "https://jobs.exoscale.com/",
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "CDN service",
            "asset_type": "Other",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Marketplace products",
            "asset_type": "Other",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "fastmail-bug-bounty",
      "name": "Fastmail Bug Bounty",
      "operator": "Fastmail Pty Ltd",
      "platform": "Direct vendor program",
      "program_url": "https://www.fastmail.com/bug-bounty/",
      "policy_url": "https://www.fastmail.com/bug-bounty/",
      "announcement_urls": [],
      "change_log_url": null,
      "last_verified_at": "2026-10-03T03:20:30Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The official policy explicitly offers monetary bounties for eligible reports.",
        "source_ids": [
          "policy"
        ]
      },
      "rewards": {
        "currency": "USD",
        "minimum": 100,
        "maximum": 5000,
        "basis": "advertised_not_individual_award",
        "summary": "Qualifying reports advertise USD 100–5,000, determined by severity and affected users at Fastmail’s discretion. Payments are processed monthly through PayPal; recipients bear taxes and fees. These are guidelines, not individual awards.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "First reports must demonstrate a qualifying threat to private user data or infrastructure. Use controlled test accounts; interacting with another account requires its owner’s consent. Responsible disclosure and reasonable remediation time are required.",
        "source_ids": [
          "policy"
        ]
      },
      "restrictions": {
        "summary": "Protect data integrity, privacy and service availability. Disruption and social engineering are prohibited. Intended email behavior, unlikely-interaction findings, third-party services, username enumeration, obsolete clients and low-impact metadata are excluded.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The policy expressly invites immediate email reports and commits to investigating all legitimate submissions. This is published intake evidence, not a delivery test.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "The reward sentence explicitly uses US$ for its minimum; the adjoining dollar maximum belongs to that same schedule.",
        "No revision date, change log, age or residency criterion was established. No submission was made. Live terms prevail; no testing authorization is granted."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Fastmail Security Issue Reporting",
          "url": "https://www.fastmail.com/bug-bounty/",
          "publisher": "Fastmail Pty Ltd",
          "retrieved_at": "2026-10-03T03:20:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Fastmail security issue reporting policy",
          "url": "https://www.fastmail.com/bug-bounty/",
          "publisher": "Fastmail Pty Ltd",
          "retrieved_at": "2026-10-03T15:03:35Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "scope_context": {
        "included_summary": "Fastmail-operated code and infrastructure; qualifying issues must threaten private data or infrastructure access.",
        "excluded_summary": "Third-party browser-extension weaknesses and XSS confined to isolated user-content hosting are excluded.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://www.fastmail.com/bug-bounty/"
        ],
        "verified_at": "2026-10-03T03:20:30Z"
      },
      "asset_scope": {
        "capture_status": "policy_defined",
        "collection_method": "official_policy_page",
        "verified_at": "2026-10-03T15:03:35Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "Fastmail-operated code and infrastructure",
            "asset_type": "policy_category",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Qualifying impact must involve private user data or Fastmail infrastructure."
          },
          {
            "name": "app.fastmail.com",
            "asset_type": "website",
            "location": "https://app.fastmail.com",
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Named as an example within the XSS-eligible *.fastmail.com domain."
          }
        ],
        "out_of_scope": [
          {
            "name": "user.fm",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "XSS on this isolated user-content host is explicitly excluded; this is not a claim that every vulnerability type is excluded."
          },
          {
            "name": "fastmailusercontent.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "XSS on this isolated user-content host is explicitly excluded; this is not a claim that every vulnerability type is excluded."
          },
          {
            "name": "www.fastmailfbl.com",
            "asset_type": "website",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Associated site not operated by Fastmail; not bounty eligible."
          }
        ],
        "limitations": [
          "The policy defines impact and ownership requirements, not a complete list of Fastmail-operated hosts.",
          "The two user-content domain exclusions are specific to XSS."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "github-bug-bounty",
      "name": "GitHub Bug Bounty",
      "operator": "GitHub",
      "platform": "HackerOne submission channel",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "rewards"
        ]
      },
      "program_url": "https://bounty.github.com/",
      "policy_url": "https://bounty.github.com/rules",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Public-program guidelines list $250 low, $2,000 medium, $5,000 high and $10,000 critical. Defense-in-depth reports receive merchandise. Private-program figures are separate.",
        "source_ids": [
          "rewards"
        ]
      },
      "eligibility": {
        "summary": "First reproducible report; current employees/contractors and those within six months of leaving are excluded. Sanctions and legal requirements apply.",
        "source_ids": [
          "policy"
        ]
      },
      "restrictions": {
        "summary": "Protect others’ information; no social engineering, physical attacks, volumetric disruption, spam or excessive automation. Product-specific exclusions apply; coordinate disclosure until a fix is public.",
        "source_ids": [
          "policy",
          "exclusions"
        ]
      },
      "last_verified_at": "2026-10-03T03:41:39Z",
      "limitations": [
        "Official GitHub-hosted rules were retrieved; the HackerOne submission page required JavaScript and was not independently reviewed as policy evidence.",
        "Published reward amounts are discretionary guidelines, not fixed payouts.",
        "Dollar signs are shown without an explicit ISO currency code in reviewed pages; currency-normalized bounds remain null.",
        "No dedicated policy change-log URL was verified.",
        "Scope and exclusion pages were freshly reviewed; reward guidelines retain their earlier retrieval date. Product-specific policy subpages and full revision history were not exhaustively reviewed.",
        "High-level coverage and exclusion context only. Asset inventories and testing instructions are omitted; current official terms prevail and this record grants no authorization."
      ],
      "sources": [
        {
          "id": "program",
          "title": "GitHub Bug Bounty",
          "url": "https://bounty.github.com/",
          "publisher": "GitHub",
          "retrieved_at": "2026-10-03T03:38:24Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "rewards",
          "title": "GitHub reward guidelines",
          "url": "https://bounty.github.com/rewards",
          "publisher": "GitHub",
          "retrieved_at": "2026-10-02T21:01:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "policy",
          "title": "GitHub program rules",
          "url": "https://bounty.github.com/rules",
          "publisher": "GitHub",
          "retrieved_at": "2026-10-03T03:38:24Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "exclusions",
          "title": "GitHub ineligible submissions",
          "url": "https://bounty.github.com/ineligible",
          "publisher": "GitHub",
          "retrieved_at": "2026-10-03T03:39:41Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "scope",
          "title": "GitHub high-level program scope policy",
          "url": "https://bounty.github.com/scope",
          "publisher": "GitHub",
          "retrieved_at": "2026-10-03T03:38:36Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "GitHub Bug Bounty scope",
          "url": "https://bounty.github.com/scope",
          "publisher": "GitHub",
          "retrieved_at": "2026-10-03T15:03:35Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-targets-2026-10-03",
          "title": "GitHub Bug Bounty target directory",
          "url": "https://bounty.github.com/targets",
          "publisher": "GitHub",
          "retrieved_at": "2026-10-03T15:03:35Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "submission_status": {
        "value": "unknown",
        "summary": "Official policy reviewed, but a live submission-acceptance indicator was not separately established.",
        "source_ids": []
      },
      "official_program_links": [
        {
          "url": "https://hackerone.com/github",
          "source_ids": [
            "program"
          ],
          "note": "GitHub’s official program homepage links to this HackerOne submission program. This verifies identity, not the dynamically rendered HackerOne policy."
        }
      ],
      "scope_context": {
        "included_summary": "Selected code-hosting, package-registry, developer-client, enterprise and supporting service categories; inclusion depends on the official product and scope policies.",
        "excluded_summary": "Unlisted products, third-party services and most hosted open-source projects are excluded; specified community, marketing, commerce and email services are also excluded. Local-access-dependent findings, network denial-of-service, intended execution within granted trust boundaries and abuse without security impact are ineligible. Upstream flaws generally belong with maintainers; known-vulnerability reports require demonstrated impact and at least 30 days since public disclosure. Product-specific exceptions remain.",
        "source_ids": [
          "scope",
          "exclusions"
        ],
        "policy_urls": [
          "https://bounty.github.com/scope",
          "https://bounty.github.com/ineligible"
        ],
        "verified_at": "2026-10-03T03:41:39Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_policy_page",
        "verified_at": "2026-10-03T15:03:35Z",
        "source_ids": [
          "assets-scope-2026-10-03",
          "assets-targets-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "github.com and its subdomains",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Subject to the explicit exceptions and target-specific policy pages."
          },
          {
            "name": "*.githubassets.com",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Subject to the explicit exceptions and target-specific policy pages."
          },
          {
            "name": "*.githubusercontent.com",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Subject to the explicit exceptions and target-specific policy pages."
          },
          {
            "name": "*.githubapp.com",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Subject to the explicit exceptions and target-specific policy pages."
          },
          {
            "name": "*.githubwebhooks.net",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Subject to the explicit exceptions and target-specific policy pages."
          },
          {
            "name": "*.github.net",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Subject to the explicit exceptions and target-specific policy pages."
          },
          {
            "name": "*.npmjs.com",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Subject to the explicit exceptions and target-specific policy pages."
          },
          {
            "name": "*.npmjs.org",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Subject to the explicit exceptions and target-specific policy pages."
          },
          {
            "name": "GitHub.com",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub API",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub CSP",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Actions",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Pages",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Gist",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Enterprise Server",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Enterprise Cloud",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "Dependabot",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Desktop",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Mobile",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub CLI",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Copilot App",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Codespaces",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Copilot",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Education",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "GitHub Credentials",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "npm Registry",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          },
          {
            "name": "npm CLI",
            "asset_type": "product",
            "location": null,
            "group": "Target directory",
            "source_ids": [
              "assets-targets-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "blog.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "community.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "email.enterprise.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "email.finance.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "email.staging.finance.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "email.support.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "email.verify.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "google7650dcf6146f04d8.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "k1._domainkey.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "k1._domainkey.mcmail.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "mcmail.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "resources.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "*.resources.github.com",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "sgmail.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "*.sgmail.github.com",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "shop.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "smtp.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "*.smtp.github.com",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "livesend.github.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "atom-io.githubapp.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "atom-io-staging.githubapp.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "email.enterprise-staging.githubapp.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "email.haystack.githubapp.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          },
          {
            "name": "reply.githubapp.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicit exception to the applicable in-scope wildcard."
          }
        ],
        "limitations": [
          "The target directory is a high-level product index; individual target pages may narrow eligibility.",
          "Unlisted products and GitHub-owned domains are excluded by the official policy; the enumerated exceptions are not the only possible exclusions."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "gitlab-bug-bounty",
      "name": "GitLab Bug Bounty",
      "operator": "GitLab",
      "platform": "HackerOne",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://hackerone.com/gitlab?type=team",
      "policy_url": "https://hackerone.com/gitlab?type=team",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Advertised ranges: Low $100–$750; Medium $1,000–$2,500; High $5,000–$15,000; Critical $20,000–$35,000. Business impact and reduced category schedules affect awards.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Current employees are excluded; former employees, immediate family and potentially conflicted associates receive additional review. Reports require verifiable evidence.",
        "source_ids": [
          "policy"
        ]
      },
      "restrictions": {
        "summary": "Privacy violations, disruption, unverified automated reports and third-party/customer installations are excluded. A shared mitigation generally receives one award; GitLab determines severity and payment.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-02T21:10:00Z",
      "limitations": [
        "Browser-rendered policy reviewed; static retrieval returned a JavaScript placeholder.",
        "Policy updated July 21, 2026; the displayed reward-table date is November 22, 2021. Its age is retained rather than assumed obsolete.",
        "Only dollar signs appear; ISO currency and normalized bounds remain null. Full live policy includes additional conditions."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "GitLab Bug Bounty | Bounty Policy | HackerOne",
          "url": "https://hackerone.com/gitlab?type=team",
          "publisher": "GitLab / HackerOne",
          "retrieved_at": "2026-10-02T21:10:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published HackerOne structured scope",
          "url": "https://hackerone.com/gitlab/policy_scopes",
          "publisher": "GitLab",
          "retrieved_at": "2026-10-03T14:59:12Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "submission_status": {
        "value": "unknown",
        "summary": "An enabled submission link and no pause notice were observed, but submission acceptance was not tested or explicitly stated.",
        "source_ids": [
          "policy"
        ]
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:59:12Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "*.gitlab.net",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "*.gitlab.org",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "*.gitlap.com",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "customers.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "registry.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "about.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "docs.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "design.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "advisories.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://gitlab.com/gitlab-org/gitlab",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://gitlab.com/gitlab-org/gitlab-runner",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://gitlab.com/gitlab-org/gitaly",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://gitlab.com/gitlab-org/gitlab-pages",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://gitlab.com/gitlab-org/gitlab-shell",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://gitlab.com/gitlab-org/gitlab-vscode-extension",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "Your Own GitLab Instance",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "Other non-production infrastructure",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "GitLab for Jira Cloud",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          }
        ],
        "out_of_scope": [
          {
            "name": "*.gitlab.cn",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "*.runway.gitlab.net",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "*.gitlab-private.org",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "*.service-now.com",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "dashboards.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "alerts.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "support.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "shop.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "forum.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "status.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "partners.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "aptly.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "translate.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "federal-support.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "us-federal-gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "ir.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "levelup.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "gitlab.biterg.io",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "gitlabsandbox.net",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "gitlabdemo.cloud",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "gitlabtraining.cloud",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "packages.gitlab.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "https://gitlab.com/gitlab-org/cli/",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "https://gitlab.com/gitlab-org/opstrace/opstrace-ui",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "https://gitlab.com/gitlab-org/opstrace/opstrace",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          }
        ],
        "limitations": [
          "Published structured-scope rows were captured. Submission eligibility and bounty eligibility differ; program policy text may add restrictions."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "grafana-labs-vulnerability-disclosure",
      "name": "Grafana Labs Vulnerability Disclosure Program",
      "operator": "Grafana Labs",
      "platform": "Intigriti",
      "program_type": {
        "value": "vulnerability_disclosure",
        "summary": "Explicitly unpaid public disclosure program; the separately described invite-only paid program is not this identity.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://app.intigriti.com/programs/grafanalabs/grafanalabsvdp",
      "policy_url": "https://app.intigriti.com/programs/grafanalabs/grafanalabsvdp",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "No monetary bounties. Valid original findings may receive public recognition and associated CVEs where applicable.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Human-validated reproducible reports with concrete impact are required; sanctions restrictions apply. Platform participation requires adulthood or guardian-approved age 16, and legal/employer eligibility.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Disclosure requires written consent. Spam, social engineering and physical intrusion are prohibited. Generic rules exclude automated scanning/reporting, while human-validated AI assistance is permitted.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Logged-out policy and login invitation do not independently verify current acceptance.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T03:58:15Z",
      "limitations": [
        "No dedicated announcement archive or policy revision date was established.",
        "Logged-out text review; authenticated eligibility and incorporated documents were not exhaustively checked.",
        "High-level summaries omit inventories and testing instructions. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Grafana Labs Vulnerability Disclosure Program policy",
          "url": "https://app.intigriti.com/programs/grafanalabs/grafanalabsvdp",
          "publisher": "Grafana Labs / Intigriti",
          "retrieved_at": "2026-10-03T03:56:33Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T03:57:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/grafanalabs/grafanalabsvdp/detail",
          "publisher": "Grafana Labs",
          "retrieved_at": "2026-10-03T14:56:03Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Designated open-source observability code and first-party plugins, limited to latest releases or the main branch when unreleased.",
        "excluded_summary": "Enterprise-dependent findings, community plugins, expected privileged behaviors, development-only functionality and specified low-impact classes are excluded. Database and denial-of-service exclusions vary by component.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/grafanalabs/grafanalabsvdp"
        ],
        "verified_at": "2026-10-03T03:58:15Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:03Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "https://github.com/grafana/grafana",
            "asset_type": "Source code",
            "location": "https://github.com/grafana/grafana",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Non-Core Grafana Plugins",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://github.com/grafana/alloy",
            "asset_type": "Source code",
            "location": "https://github.com/grafana/alloy",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://github.com/grafana/faro-web-sdk",
            "asset_type": "Source code",
            "location": "https://github.com/grafana/faro-web-sdk",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://github.com/grafana/k6",
            "asset_type": "Source code",
            "location": "https://github.com/grafana/k6",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://github.com/grafana/beyla",
            "asset_type": "Source code",
            "location": "https://github.com/grafana/beyla",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://github.com/grafana/pyroscope",
            "asset_type": "Source code",
            "location": "https://github.com/grafana/pyroscope",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://github.com/grafana/loki",
            "asset_type": "Source code",
            "location": "https://github.com/grafana/loki",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://github.com/grafana/mimir",
            "asset_type": "Source code",
            "location": "https://github.com/grafana/mimir",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://github.com/grafana/tempo",
            "asset_type": "Source code",
            "location": "https://github.com/grafana/tempo",
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://github.com/grafana/*",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "hackerone-security-bounty",
      "name": "HackerOne Security Bounty",
      "operator": "HackerOne",
      "platform": "HackerOne",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://hackerone.com/security?type=team",
      "policy_url": "https://hackerone.com/security?type=team",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Advertised ranges: Low $100–$200; Medium $1,000–$1,500; High $3,000–$7,000; Critical $6,000–$15,000.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Program compliance is required for reward eligibility. Employment-exclusive findings and unapproved report sources can be ineligible.",
        "source_ids": [
          "policy"
        ]
      },
      "restrictions": {
        "summary": "Do not access customer programs, environments or data, or unauthorized third-party infrastructure. Encountering sensitive information requires stopping and notifying the program.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-02T21:09:00Z",
      "limitations": [
        "Policy and reward table were reviewed in the browser; static retrieval returned a JavaScript placeholder.",
        "The page displays policy update September 24, 2026 and reward-table update July 28, 2026.",
        "Only dollar signs appear; ISO currency and normalized bounds remain null. Requirements are not exhaustively reproduced."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "HackerOne Security Bounty | Bounty Policy | HackerOne",
          "url": "https://hackerone.com/security?type=team",
          "publisher": "HackerOne / HackerOne",
          "retrieved_at": "2026-10-02T21:09:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published HackerOne structured scope",
          "url": "https://hackerone.com/security/policy_scopes",
          "publisher": "HackerOne",
          "retrieved_at": "2026-10-03T14:59:13Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "submission_status": {
        "value": "unknown",
        "summary": "An enabled submission link and no pause notice were observed, but submission acceptance was not tested or explicitly stated.",
        "source_ids": [
          "policy"
        ]
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:59:13Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "hackerone.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "api.hackerone.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "www.hackerone.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "app.pullrequest.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "reviewer.pullrequest.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "hackerone-us-west-2-production-attachments.s3.us-west-2.amazonaws.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "www.wearehackerone.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "mta-sts.wearehackerone.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "errors.hackerone.net",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://*.hackerone-ext-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "a5s.hackerone-ext-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "b5s.hackerone-ext-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "hackerone-ext-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://*.hackerone-user-content.com/",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "ctf.hacker101.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "hackathon-photos.hackerone-user-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "cover-photos.hackerone-user-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "hackathon-photos-us-east-2.hackerone-user-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "profile-photos.hackerone-user-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "hackerone-user-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "profile-photos-us-east-2.hackerone-user-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "cover-photos-us-east-2.hackerone-user-content.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "hackerone.live",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "*.vpn.hackerone.net",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://hackerone.com/mcp",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/Hacker0x01/react-datepicker",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          }
        ],
        "out_of_scope": [
          {
            "name": "support.hackerone.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "go.hacker.one",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "info.hacker.one",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "ma.hacker.one",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "h1.community",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "www.h1.community",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "www.hackeronestatus.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          },
          {
            "name": "hackerone-swag.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          }
        ],
        "limitations": [
          "Published structured-scope rows were captured. Submission eligibility and bounty eligibility differ; program policy text may add restrictions."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "hostgator-latam-bug-bounty",
      "name": "HostGator LATAM Bug Bounty",
      "operator": "Newfold Digital / HostGator LATAM",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The official brief advertises monetary bounties.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/hostgator-latam-bb",
      "policy_url": "https://bugcrowd.com/engagements/hostgator-latam-bb",
      "announcement_urls": [
        "https://bugcrowd.com/engagements/hostgator-latam-bb/announcements"
      ],
      "change_log_url": "https://bugcrowd.com/engagements/hostgator-latam-bb/changelog",
      "rewards": {
        "currency": "USD",
        "minimum": 250,
        "maximum": 2500,
        "basis": "advertised_not_individual_award",
        "summary": "Advertised P3–P1 bands span USD 250–2,500; severity, likelihood and impact affect discretionary awards. Shared causes receive one bounty.",
        "source_ids": [
          "policy",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "Newfold group employees, their families, current vendors and vendor employees are excluded; sanctions apply. Platform first-valid-report rules apply; monetary compensation requires age 18 or the applicable age of majority.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Owned/authorized accounts only; no real-customer interaction, multiple accounts, brute force, social engineering, disruption or data damage. Public disclosure is prohibited; safe harbor is conditional.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "Current In progress status and a September 2026 participation invitation supersede the historical March 2022 pause notice.",
        "source_ids": [
          "policy",
          "announcements"
        ]
      },
      "last_verified_at": "2026-10-03T04:12:42Z",
      "limitations": [
        "Brief revision: September 11, 2026. Change index: page 1 of 2 only; version diffs unreviewed.",
        "USD uses platform accounting evidence. Browser review recovered text omitted by static retrieval.",
        "Announcement index and historical pause body reviewed; other notices read within the brief. No authenticated intake or complete legal audit. Inventories/instructions omitted; live terms prevail. No authorization granted."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "HostGator LATAM Bug Bounty public brief",
          "url": "https://bugcrowd.com/engagements/hostgator-latam-bb",
          "publisher": "Newfold Digital / HostGator LATAM / Bugcrowd",
          "retrieved_at": "2026-10-03T04:10:04Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "announcements",
          "title": "HostGator LATAM Bug Bounty announcement archive",
          "url": "https://bugcrowd.com/engagements/hostgator-latam-bb/announcements",
          "publisher": "Newfold Digital / HostGator LATAM / Bugcrowd",
          "retrieved_at": "2026-10-03T04:11:40Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "changelog",
          "title": "HostGator LATAM Bug Bounty change index",
          "url": "https://bugcrowd.com/engagements/hostgator-latam-bb/changelog",
          "publisher": "Newfold Digital / HostGator LATAM / Bugcrowd",
          "retrieved_at": "2026-10-03T04:12:14Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd Organization Accounting",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T04:09:31Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T04:10:21Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/hostgator-latam-bb/changelog/e57fb9c2-18c7-4440-891f-d7fd8857088c.json",
          "publisher": "Newfold Digital / HostGator LATAM",
          "retrieved_at": "2026-10-03T14:56:05Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Selected first-party hosting and billing services, including qualifying authenticated navigation; recent coverage emphasizes AI-assisted server-management functionality.",
        "excluded_summary": "Unlisted and customer-controlled services, third-party components, chatboxes, source disclosure, external credential leaks, recent disclosures and specified low-impact classes are excluded.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://bugcrowd.com/engagements/hostgator-latam-bb"
        ],
        "verified_at": "2026-10-03T04:12:42Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:05Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "www.hostgator.com.br/",
            "asset_type": "website",
            "location": "https://www.hostgator.com.br/",
            "group": "In Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://financeiro.hostgator.com.br",
            "asset_type": "website",
            "location": "https://financeiro.hostgator.com.br",
            "group": "In Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "https://carrinho.hostgator.com.br/",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "academy.hostgator.com",
            "asset_type": "website",
            "location": "https://www.academy.hostgator.com",
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.hostgator.com.br",
            "asset_type": "website",
            "location": "https://www.hostgator.com.br",
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.hostgator.mx",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "intel-vulnerability-disclosure",
      "name": "Intel Vulnerability Disclosure Program",
      "operator": "Intel",
      "platform": "Intigriti",
      "program_type": {
        "value": "vulnerability_disclosure",
        "summary": "Explicit no-bounty disclosure program; monetary bonuses are also excluded.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://app.intigriti.com/programs/intel/intelvulnerabilitydisclosureprogram",
      "policy_url": "https://app.intigriti.com/programs/intel/intelvulnerabilitydisclosureprogram",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Null currency/bounds are inapplicable. Acknowledgment or reputation credit is not payment.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Age 18 minimum; minors need guardian permission. Employer-representative reporting needs written approval. Sanctions and six-month employee/contractor/family/household exclusions apply. Reports must be original, confidential and evidenced on supported public versions.",
        "source_ids": [
          "policy"
        ]
      },
      "restrictions": {
        "summary": "Others’ data cannot be accessed or retained; accidental exposure requires stopping and reporting. Disclosure needs written consent. Safe harbor excludes third parties.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Visible policies and login invitations do not verify acceptance.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T03:41:28Z",
      "limitations": [
        "End-of-life reporting remains encouraged despite reward exclusion; reputation eligibility is distinct.",
        "No announcement/archive change-log verified; external conduct/disclosure policies remain unreviewed.",
        "Logged-out review; authenticated eligibility and open/paused status unverified.",
        "High-level context omits asset inventories and testing instructions. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Intel Vulnerability Disclosure Program policy",
          "url": "https://app.intigriti.com/programs/intel/intelvulnerabilitydisclosureprogram",
          "publisher": "Intel / Intigriti",
          "retrieved_at": "2026-10-03T03:39:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/intel/intelvulnerabilitydisclosureprogram/detail",
          "publisher": "Intel",
          "retrieved_at": "2026-10-03T14:56:06Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Maintained Intel-branded hardware, firmware, software and customer-facing services across computing, networking, storage, graphics and cloud categories. Solely Intel-maintained open-source projects qualify; other projects depend on maintainers’ policies.",
        "excluded_summary": "Third-party, licensed-product-specific, prerelease, divested, prototyping and internal-IT categories; exposed credentials, duplicates, social engineering and specified physical-access findings. Acquisitions need six months and PSIRT support. Intel-rooted issues in third-party products remain reportable.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/intel/intelvulnerabilitydisclosureprogram"
        ],
        "verified_at": "2026-10-03T03:41:28Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:06Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "Software",
            "asset_type": "Other",
            "location": null,
            "group": "No bounty",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Firmware",
            "asset_type": "Other",
            "location": null,
            "group": "No bounty",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Hardware",
            "asset_type": "Other",
            "location": null,
            "group": "No bounty",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Services",
            "asset_type": "Other",
            "location": null,
            "group": "No bounty",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "platform": "Intigriti",
      "program_type": {
        "value": "vulnerability_disclosure",
        "summary": "The policy explicitly describes a disclosure program without monetary bounties.",
        "source_ids": [
          "policy"
        ]
      },
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "No monetary bounty schedule; currency and numeric bounds remain null.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Logged-out policy and login invitation do not independently establish current intake status.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T04:29:23Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "id": "ivo-ai-vulnerability-disclosure",
      "name": "Ivo AI Vulnerability Disclosure Program",
      "operator": "Ivo AI",
      "program_url": "https://app.intigriti.com/programs/ivoai/ivovulnerabilitydisclosureprogram",
      "policy_url": "https://app.intigriti.com/programs/ivoai/ivovulnerabilitydisclosureprogram",
      "eligibility": {
        "summary": "Platform membership and researcher identification are required. The program currently supplies no credentials; internally known findings count as duplicates. Platform eligibility requires age 18, or 16 with guardian permission, plus legal and employer authorization.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Activity must cease upon unintended sensitive-data or cross-account access. Disclosure needs written consent; disruption, social engineering, physical intrusion and brute force are prohibited.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "The no-bounty policy allows an exception only if Ivo expressly confirms it; no such commitment was established.",
        "No announcement archive or complete revision history was established. Expanded safe-harbor terms and other incorporated documents remain unreviewed.",
        "Logged-out review; summaries omit inventories and procedures. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Ivo AI Vulnerability Disclosure Program policy",
          "url": "https://app.intigriti.com/programs/ivoai/ivovulnerabilitydisclosureprogram",
          "publisher": "Ivo AI / Intigriti",
          "retrieved_at": "2026-10-03T04:28:36Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T04:29:02Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/ivoai/ivovulnerabilitydisclosureprogram/detail",
          "publisher": "Ivo AI",
          "retrieved_at": "2026-10-03T14:56:08Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "scope_context": {
        "included_summary": "Approved legal-document application, public API and document-editor integration categories, including identity controls, confidentiality and tenant separation.",
        "excluded_summary": "Unlisted systems, uncontrolled third-party integrations, corporate/internal services, low-impact configuration findings, unsupported software and compromised-device scenarios are excluded.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/ivoai/ivovulnerabilitydisclosureprogram"
        ],
        "verified_at": "2026-10-03T04:29:23Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:08Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "*.latchapp.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://app.ivo.ai/*",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "All Ivo public APIs",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Ivo Microsoft Word add-in",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "launchdarkly-managed-bug-bounty",
      "name": "LaunchDarkly Managed Bug Bounty Engagement",
      "operator": "LaunchDarkly",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/launchdarkly-mbb-og",
      "policy_url": "https://bugcrowd.com/engagements/launchdarkly-mbb-og",
      "announcement_urls": [],
      "change_log_url": null,
      "last_verified_at": "2026-10-02T23:00:00Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "rewards": {
        "currency": "USD",
        "minimum": 150,
        "maximum": 7500,
        "basis": "advertised_not_individual_award",
        "summary": "Advertised schedule: P4 $150, P3 $1,250, P2 $2,500 and P1 $6,500–$7,500. Severity uses CVSS with impact/likelihood adjustments and an appeal opportunity. These are guidelines, not actual individual awards.",
        "source_ids": [
          "policy",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "The June 3, 2026 announcement makes participation public without invitations. Accounts must follow researcher identification rules. Reports require original human analysis and reproducible security impact. Platform reward eligibility includes first valid reporting and applicable adulthood requirements.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Scope includes selected application, API, SDK and supporting services. Unlisted properties, third-party integrations, support interfaces, non-SDK repositories, scan-only results, low-impact findings, denial-of-service and social engineering are excluded. Protect other users’ data and service stability. Public disclosure is prohibited; safe harbor is conditional.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "Official brief displays In progress, an ongoing period and a Submit report link. Individual eligibility still depends on live terms.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "Brief displays August 13, 2026 as its update date.",
        "The brief permits certain researcher-identifying email alternatives, while the displayed June 24, 2026 announcement requires the platform email alias exclusively. This inconsistency needs program clarification; no broader permission is inferred.",
        "USD normalization relies on Bugcrowd accounting documentation because the brief uses dollar signs.",
        "The page and its displayed announcements were read in the cloud browser; linked announcement archives and authenticated submission flow were not reviewed. This summary omits asset inventories and grants no testing permission."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "LaunchDarkly public program brief",
          "url": "https://bugcrowd.com/engagements/launchdarkly-mbb-og",
          "publisher": "LaunchDarkly / Bugcrowd",
          "retrieved_at": "2026-10-02T23:00:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd Organization Accounting",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-02T23:00:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-02T23:00:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/launchdarkly-mbb-og/changelog/884450ef-4277-41a9-8394-5f8c49cae2d8.json",
          "publisher": "LaunchDarkly",
          "retrieved_at": "2026-10-03T14:56:09Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:09Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "app.launchdarkly.com",
            "asset_type": "website",
            "location": null,
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "events.launchdarkly.com",
            "asset_type": "website",
            "location": null,
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "stream.launchdarkly.com",
            "asset_type": "website",
            "location": null,
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "LaunchDarkly Open Source SDKs",
            "asset_type": "other",
            "location": null,
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "docs.launchdarkly.com",
            "asset_type": "website",
            "location": null,
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://launchdarkly.com/docs",
            "asset_type": "website",
            "location": "https://launchdarkly.com/docs",
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "blog.launchdarkly.com",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "launchdarkly.com",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "sandbox.launchdarkly.com",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "slack.launchdarkly.com",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "status.launchdarkly.com",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "launchdarkly.atlassian.net",
            "asset_type": "other",
            "location": "https://launchdarkly.atlassian.net",
            "group": "Out of Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "matlab-online-bug-bounty",
      "name": "MATLAB Online - Ongoing Bug Bounty Engagement",
      "operator": "MathWorks",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/matlab-online",
      "policy_url": "https://bugcrowd.com/engagements/matlab-online",
      "announcement_urls": [
        "https://bugcrowd.com/engagements/matlab-online/announcements"
      ],
      "change_log_url": "https://bugcrowd.com/engagements/matlab-online/changelog",
      "rewards": {
        "currency": "USD",
        "minimum": 200,
        "maximum": 7000,
        "basis": "advertised_not_individual_award",
        "summary": "Advertised bands: P4 $200–$250, P3 $550–$750, P2 $1,200–$3,000 and P1 $3,000–$7,000. Priority may change with impact; some stored-script findings default to P3 unless broader impact is established. No individual award is asserted.",
        "source_ids": [
          "policy",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "Designated researcher accounts and trial-license association are required, with activity limited to content they created. Reports need original analysis and reproducible impact; related instances generally share one report. Platform first-valid-report rules apply; monetary compensation requires age 18 or the applicable age of majority.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Intended execution of user-supplied code is not itself a security finding. Unlisted properties and third-party services are excluded. No staff contact through product features, service disruption or persistent public content. Low-impact configuration findings are generally excluded. Public disclosure is prohibited; safe harbor is conditional.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The official brief explicitly displays In progress and an ongoing period, with a submission link. Individual eligibility remains subject to live terms.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T01:52:33Z",
      "limitations": [
        "Brief and reviewed change index show September 3, 2026 as the latest revision; individual diffs were not opened.",
        "The separately opened announcement archive explicitly contains no announcements. The separate unpaid disclosure route and license enrollment flow were not reviewed.",
        "USD normalization uses platform accounting documentation; the brief itself uses dollar signs. No individual award or payment is established.",
        "Public policy pages only; authenticated submission and incorporated legal documents were not exhaustively reviewed. Asset inventories and testing instructions are omitted. Live terms prevail; this summary grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "MATLAB Online - Ongoing Bug Bounty Engagement public brief",
          "url": "https://bugcrowd.com/engagements/matlab-online",
          "publisher": "MathWorks / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "announcements",
          "title": "MATLAB Online - Ongoing Bug Bounty Engagement announcements",
          "url": "https://bugcrowd.com/engagements/matlab-online/announcements",
          "publisher": "MathWorks / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "changelog",
          "title": "MATLAB Online - Ongoing Bug Bounty Engagement change index",
          "url": "https://bugcrowd.com/engagements/matlab-online/changelog",
          "publisher": "MathWorks / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd Organization Accounting",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/matlab-online/changelog/6b90f7f3-355b-406d-848e-3dfb0622f02a.json",
          "publisher": "MathWorks",
          "retrieved_at": "2026-10-03T14:56:10Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:10Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "https://matlab.mathworks.com/ [MATLAB ONLINE]",
            "asset_type": "website",
            "location": "https://matlab.mathworks.com/",
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "microsoft-edge-bug-bounty",
      "name": "Microsoft Edge Bounty Program",
      "operator": "Microsoft Corporation",
      "platform": "MSRC",
      "program_url": "https://www.microsoft.com/en-us/msrc/bounty-new-edge",
      "policy_url": "https://www.microsoft.com/en-us/msrc/bounty-new-edge",
      "announcement_urls": [],
      "change_log_url": "https://www.microsoft.com/en-us/msrc/bounty-new-edge",
      "last_verified_at": "2026-10-03T03:41:39Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "rewards": {
        "currency": "USD",
        "minimum": 250,
        "maximum": 30000,
        "basis": "advertised_not_individual_award",
        "summary": "The introduction and table advertise USD 250–30,000, while award prose starts at USD 500. The lower table value is retained with that discrepancy. Higher discretionary awards are possible; one submission receives its highest qualifying award, not cumulative program payouts.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Participants must be at least 14; minors need guardian permission. Employer, sanctions and public-sector ethics requirements apply; current/recent Microsoft staff and specified related persons are excluded. New, reproducible findings are required.",
        "source_ids": [
          "guidelines"
        ]
      },
      "restrictions": {
        "summary": "Preserve customer data and availability; stop on unauthorized access, report immediately and delete retained data. No social engineering, disruptive automation, unauthorized credential use or post-compromise activity. Confidentiality continues through remediation; attack-enabling details wait another 30 days. Imposed remediation deadlines forfeit eligibility. Safe harbor is conditional.",
        "source_ids": [
          "guidelines",
          "rules"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "The policy invites portal submissions but supplies no explicit open/paused status. A visible policy and program listing do not independently establish availability.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "The program revision history ends April 7, 2026; overarching terms are dated September 3, 2026.",
        "The Edge page suggests a Standard Award Policy fallback, but that section of the linked Bounty Program Guidelines excludes endpoint/on-premises programs. Fallback eligibility is not assumed.",
        "Advertised amounts are not individual award evidence. Authenticated submission availability and payment enrollment were not tested.",
        "Public policy review only. Asset inventories and operational instructions are omitted. Live terms prevail; this summary grants no authorization or legal protection."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Microsoft Edge Bounty Program and revision history",
          "url": "https://www.microsoft.com/en-us/msrc/bounty-new-edge",
          "publisher": "Microsoft",
          "retrieved_at": "2026-10-03T03:38:36Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "guidelines",
          "title": "Microsoft Bounty Program Guidelines, terms, safe harbor and Standard Award Policy",
          "url": "https://www.microsoft.com/en-us/msrc/bounty-guidelines",
          "publisher": "Microsoft",
          "retrieved_at": "2026-10-03T03:41:08Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "rules",
          "title": "Microsoft Security Testing Rules of Engagement",
          "url": "https://www.microsoft.com/en-us/msrc/pentest-rules-of-engagement",
          "publisher": "Microsoft",
          "retrieved_at": "2026-10-03T03:41:15Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Microsoft Edge Bounty Program",
          "url": "https://www.microsoft.com/en-us/msrc/bounty-new-edge",
          "publisher": "Microsoft Corporation",
          "retrieved_at": "2026-10-03T15:03:35Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "program_type": {
        "value": "paid_bounty",
        "summary": "The official policy advertises monetary bounties for eligible reports.",
        "source_ids": [
          "policy"
        ]
      },
      "scope_context": {
        "included_summary": "Current Chromium-based desktop and mobile browser channels and eligible embedded-browser SDKs/runtimes; included third-party components require Edge-specific security impact absent from equivalent Chrome.",
        "excluded_summary": "Canary-only builds, Internet Explorer, EdgeHTML, experimental features, user-generated content, kiosk escapes, denial-of-service and supporting documentation/community sites are excluded. Already-public findings, outdated libraries alone, unlikely-interaction scenarios and downgraded protections generally do not qualify; AI and identity findings may belong to separate programs.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://www.microsoft.com/en-us/msrc/bounty-new-edge"
        ],
        "verified_at": "2026-10-03T03:41:39Z"
      },
      "asset_scope": {
        "capture_status": "policy_defined",
        "collection_method": "official_policy_page",
        "verified_at": "2026-10-03T15:03:35Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "Microsoft Edge based on Chromium",
            "asset_type": "product",
            "location": null,
            "group": "Dev, Beta and Stable",
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Latest supported version; qualifying findings must not reproduce in equivalent Chrome channel."
          },
          {
            "name": "WebView2 SDK",
            "asset_type": "software",
            "location": null,
            "group": "Prerelease and release",
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Current SDK on a fully patched supported Windows version."
          },
          {
            "name": "WebView2 runtime",
            "asset_type": "software",
            "location": null,
            "group": "Evergreen, Edge Dev and Beta runtimes",
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Current runtime on a fully patched supported Windows version."
          }
        ],
        "out_of_scope": [
          {
            "name": "Internet Explorer",
            "asset_type": "product",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Microsoft Edge based on EdgeHTML",
            "asset_type": "product",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Versions through 45."
          },
          {
            "name": "Microsoft Edge Canary-only builds",
            "asset_type": "software",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Findings that reproduce only in Canary are excluded."
          },
          {
            "name": "Edge training, documentation, sample and community sites",
            "asset_type": "policy_category",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Excluded from this bounty program's awards."
          }
        ],
        "limitations": [
          "This product bounty is version- and impact-dependent; the list describes products, not web target domains."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "moovit-managed-bug-bounty",
      "name": "Moovit Managed Bug Bounty Program",
      "operator": "Moovit",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy",
          "announcements"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/moovit-mbb-og",
      "policy_url": "https://bugcrowd.com/engagements/moovit-mbb-og",
      "announcement_urls": [
        "https://bugcrowd.com/engagements/moovit-mbb-og/announcements"
      ],
      "change_log_url": "https://bugcrowd.com/engagements/moovit-mbb-og/changelog",
      "rewards": {
        "currency": "USD",
        "minimum": 100,
        "maximum": 3500,
        "basis": "advertised_not_individual_award",
        "summary": "Ordinary advertised bands are P4 $100–$250, P3 $250–$750, P2 $1,000–$2,000 and P1 $2,000–$3,500. A still-visible doubled schedule reaches $7,000, but the reviewed notice dates that campaign to July 7–22, 2025; it is excluded from normalized bounds. Awards remain discretionary.",
        "source_ids": [
          "policy",
          "announcements",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "The public brief requires reproducible, consequential findings, researcher-identified accounts and a signed NDA as a participation condition. Only owned or expressly authorized accounts may be involved. Platform first-valid-report rules apply; monetary compensation requires age 18 or the applicable age of majority.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Scope is limited to selected mobile functionality; web applications and embedded web content are excluded. Automated scanners, bulk account creation, disruptive requests, social engineering and third-party application activity are prohibited. Minimize personal-data access. Written permission is required before disclosure.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The official brief explicitly displays In progress and an ongoing period, with a submission link. Individual eligibility remains subject to live terms.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T01:52:33Z",
      "limitations": [
        "Brief and reviewed change index show February 12, 2026 as the latest revision; individual diffs were not opened.",
        "The announcement archive and July 7, 2025 promotion notice were opened. Its end date and stated duration are not perfectly aligned; no current bonus entitlement is inferred.",
        "NDA signing mechanics were not available in the reviewed brief and were not tested. Other archived announcement bodies were not separately opened.",
        "USD normalization uses platform accounting documentation; the brief itself uses dollar signs. No individual award or payment is established.",
        "Public policy pages only; authenticated submission and incorporated legal documents were not exhaustively reviewed. Asset inventories and testing instructions are omitted. Live terms prevail; this summary grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Moovit Managed Bug Bounty Program public brief",
          "url": "https://bugcrowd.com/engagements/moovit-mbb-og",
          "publisher": "Moovit / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "announcements",
          "title": "Moovit Managed Bug Bounty Program announcements",
          "url": "https://bugcrowd.com/engagements/moovit-mbb-og/announcements",
          "publisher": "Moovit / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "changelog",
          "title": "Moovit Managed Bug Bounty Program change index",
          "url": "https://bugcrowd.com/engagements/moovit-mbb-og/changelog",
          "publisher": "Moovit / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd Organization Accounting",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/moovit-mbb-og/changelog/6bded391-eff8-479d-a41c-4efdcee70ed0.json",
          "publisher": "Moovit",
          "retrieved_at": "2026-10-03T14:56:11Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:11Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "All In Scope Targets",
            "asset_type": "other",
            "location": null,
            "group": "Limited Double Bounty Promotion | July 7th - July 22nd",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Moovit Android App",
            "asset_type": "android",
            "location": "https://play.google.com/store/apps/details?id=com.tranzmate&hl=en_US",
            "group": "In Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Moovit iOS App",
            "asset_type": "ios",
            "location": "https://apps.apple.com/us/app/moovit-all-transit-options/id498477945",
            "group": "In Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "WayFinder - Augmented Reality helper to find your stop",
            "asset_type": "ios",
            "location": "https://support.moovitapp.com/hc/en-us/articles/11389054527122-WayFinder-Augmented-Reality-helper-to-find-your-stop-iPhone-only",
            "group": "In Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "Every Web App is Out Of Scope.",
            "asset_type": "website",
            "location": null,
            "group": "Out Of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Every app not related to the Moovit mobile application.",
            "asset_type": "other",
            "location": null,
            "group": "Out Of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Any WebView sources or web application rendered within the mobile applications",
            "asset_type": "other",
            "location": null,
            "group": "Out Of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "mozilla-client-bug-bounty",
      "name": "Mozilla Client Bug Bounty",
      "operator": "Mozilla",
      "platform": "Bugzilla",
      "program_url": "https://www.mozilla.org/en-US/security/client-bug-bounty/",
      "policy_url": "https://www.mozilla.org/en-US/security/client-bug-bounty/",
      "announcement_urls": [
        "https://hackerone.com/mozilla/updates?type=team"
      ],
      "change_log_url": null,
      "last_verified_at": "2026-10-03T03:41:39Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The official policy explicitly offers monetary bounties for eligible reports.",
        "source_ids": [
          "policy"
        ]
      },
      "rewards": {
        "currency": "USD",
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Published base ceilings are USD 3,000, 10,000 and 20,000 by impact. Certain mitigation findings receive a 50% bonus; exceptional moderate-impact reports remain discretionary. Bounds are null because no payout floor or single bonus-inclusive ceiling is stated.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Original actionable reports in supported configurations qualify; a 48-hour duplicate window may split awards. Internal discoveries and a seven-day internal-detection window can preclude payment, with exceptions. Contributors of the buggy code, employees, contractors and other business relationships are excluded. Local payment-age and US sanctions requirements apply.",
        "source_ids": [
          "policy",
          "general"
        ]
      },
      "restrictions": {
        "summary": "Protect privacy and availability, use controlled accounts, report accidental data exposure and delete retained data after notification. Allow reasonable remediation time; no extortion or personal exploitation. Safe harbor cannot bind third parties.",
        "source_ids": [
          "general"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The September 11, 2026 announcement expressly says the Firefox client program continues normally through Bugzilla despite the separate Web program’s pause.",
        "source_ids": [
          "updates"
        ]
      },
      "limitations": [
        "The FAQ identifies a February 24, 2026 reward-category change: GPU-process findings no longer receive the highest sandbox-escape category solely for that process compromise.",
        "The reviewed July 10, 2026 announcement transfers Mozilla VPN client coverage into this program. No asset inventory is reproduced.",
        "No client-specific change-log URL or overall policy revision date was established. Linked submission terms and Bugzilla etiquette were not exhaustively reviewed.",
        "No authenticated intake or payment test occurred. This policy summary is distinct from the Web program and grants no authorization.",
        "Only policy, general eligibility and FAQ sources were refreshed; announcement timestamps remain unchanged."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Mozilla Client Bug Bounty Program",
          "url": "https://www.mozilla.org/en-US/security/client-bug-bounty/",
          "publisher": "Mozilla",
          "retrieved_at": "2026-10-03T03:38:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "general",
          "title": "Mozilla Security Bug Bounty general eligibility and safe harbor",
          "url": "https://www.mozilla.org/en-US/security/bug-bounty/",
          "publisher": "Mozilla",
          "retrieved_at": "2026-10-03T03:39:31Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "faq",
          "title": "Mozilla Bug Bounty Program FAQ",
          "url": "https://www.mozilla.org/en-US/security/bug-bounty/faq/",
          "publisher": "Mozilla",
          "retrieved_at": "2026-10-03T03:38:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "updates",
          "title": "Mozilla public program updates: client continuity and policy changes",
          "url": "https://hackerone.com/mozilla/updates?type=team",
          "publisher": "Mozilla / HackerOne",
          "retrieved_at": "2026-10-03T02:31:44Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Mozilla Client Bug Bounty Program",
          "url": "https://www.mozilla.org/en-US/security/client-bug-bounty/",
          "publisher": "Mozilla",
          "retrieved_at": "2026-10-03T15:03:35Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "scope_context": {
        "included_summary": "Current desktop and mobile browser releases, supported development channels and selected mitigation protections; release-channel and configuration exceptions apply.",
        "excluded_summary": "Unbundled add-ons, routine dependency patch gaps, end-of-life products, unsupported configurations and standalone developer tools generally do not qualify. Denial-of-service-only and minor spoofing findings are usually unrewarded; administrator-installed trust roots or certificate-pinned connections invalidate mitigation claims.",
        "source_ids": [
          "policy",
          "faq"
        ],
        "policy_urls": [
          "https://www.mozilla.org/en-US/security/client-bug-bounty/",
          "https://www.mozilla.org/en-US/security/bug-bounty/faq/"
        ],
        "verified_at": "2026-10-03T03:41:39Z"
      },
      "asset_scope": {
        "capture_status": "policy_defined",
        "collection_method": "official_policy_page",
        "verified_at": "2026-10-03T15:03:35Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "Firefox desktop",
            "asset_type": "browser",
            "location": null,
            "group": "Current release and supported development channels",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Firefox for Android",
            "asset_type": "browser",
            "location": null,
            "group": "Current release and supported development channels",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Firefox for iOS",
            "asset_type": "browser",
            "location": null,
            "group": "Current release and supported development channels",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "Fennec (older Firefox for Android application)",
            "asset_type": "browser",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Explicitly excluded from exploit-mitigation bounty coverage."
          },
          {
            "name": "End-of-life Mozilla client products",
            "asset_type": "policy_category",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Not eligible for the client security bounty."
          }
        ],
        "limitations": [
          "The policy includes selected exploit mitigations and configuration exceptions; product labels alone do not capture every condition."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "mozilla-web-bug-bounty",
      "name": "Mozilla Web Bug Bounty",
      "operator": "Mozilla",
      "platform": "HackerOne",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://hackerone.com/mozilla?type=team",
      "policy_url": "https://hackerone.com/mozilla?type=team",
      "announcement_urls": [
        "https://hackerone.com/mozilla/updates?type=team"
      ],
      "change_log_url": "https://hackerone.com/mozilla/updates?type=team",
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Displayed critical-site ranges: High $3,000–$6,000 and Critical $6,000–$15,000. Core-category ranges: High $1,000–$3,000 and Critical $3,000–$5,000; special exceptions apply.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Generally original unreported findings, excluding reporters who contributed the faulty code or have a Mozilla business relationship. Age, payment and US sanctions requirements apply.",
        "source_ids": [
          "policy"
        ]
      },
      "restrictions": {
        "summary": "Low/medium reports generally receive no bounty. Respect privacy, availability and coordinated-disclosure requirements.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-02T21:10:00Z",
      "limitations": [
        "Policy and September 11, 2026 notice were directly reviewed in the browser.",
        "Displayed rewards during the web-program pause do not imply general submission availability.",
        "Only dollar signs appear; ISO currency and normalized bounds remain null. Reopening is an expectation, not a confirmed future event."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Mozilla Web Bug Bounty | Bounty Policy | HackerOne",
          "url": "https://hackerone.com/mozilla?type=team",
          "publisher": "Mozilla / HackerOne",
          "retrieved_at": "2026-10-02T21:10:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "updates",
          "title": "Mozilla Web Bug Bounty | Updates | HackerOne",
          "url": "https://hackerone.com/mozilla/updates?type=team",
          "publisher": "Mozilla / HackerOne",
          "retrieved_at": "2026-10-02T21:10:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published HackerOne structured scope",
          "url": "https://hackerone.com/mozilla/policy_scopes",
          "publisher": "Mozilla",
          "retrieved_at": "2026-10-03T14:59:14Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "submission_status": {
        "value": "paused",
        "summary": "Web submissions paused September 11, 2026; reopening expected Q1 2027. Existing reports retain current-rate handling. Critical or actively exploited web issues retain a Bugzilla route. Firefox client bounty is unaffected.",
        "source_ids": [
          "updates"
        ]
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:59:14Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "addons.allizom.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "developer.mozilla.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "accounts.firefox.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "vpn.mozilla.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "relay.firefox.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "www.mozilla.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "support.mozilla.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "hg.mozilla.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "monitor.mozilla.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "aus5.mozilla.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "bugzilla.mozilla.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "crash-reports.allizom.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "crash-stats.allizom.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "firefox-ci-tc.services.mozilla.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "firefox.settings.services.mozilla.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "lando.services.mozilla.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "merino.services.mozilla.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "phabricator.allizom.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "sync.services.mozilla.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "www.firefox.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "pontoon.allizom.org",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "Product Delivery",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "Mozilla Ad Routing Service",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "Firefox Homepage Newtab",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published structured-scope rows were captured. Submission eligibility and bounty eligibility differ; program policy text may add restrictions."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "nubank-brasil-bug-bounty",
      "name": "Nubank Brasil Managed Bug Bounty Program",
      "operator": "Nubank Brasil",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The official brief advertises monetary bounties.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/nubank",
      "policy_url": "https://bugcrowd.com/engagements/nubank",
      "announcement_urls": [
        "https://bugcrowd.com/engagements/nubank/announcements"
      ],
      "change_log_url": "https://bugcrowd.com/engagements/nubank/changelog",
      "rewards": {
        "currency": "USD",
        "minimum": 50,
        "maximum": 4000,
        "basis": "advertised_not_individual_award",
        "summary": "Ordinary tiers span USD 50–4,000, 50–2,000 and 50–1,000. June 2026 bonuses expired. A September 22–October 16, 2026 campaign offers approximately $100 extra from a dedicated pool, subject to eligibility and excluded from bounds.",
        "source_ids": [
          "policy",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "Employees and third-party providers are excluded. Bank-account access requires valid regional tax identification and approval; false identification is prohibited. Platform first-valid-report rules apply; monetary compensation requires age 18 or the applicable age of majority.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Use owned/authorized accounts, protect privacy and availability, and observe monetary limits. Social engineering and disruption are prohibited. Disclosure needs consent; safe harbor is conditional.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The official brief explicitly displays In progress and an ongoing period.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T04:12:42Z",
      "limitations": [
        "Brief revision: June 26, 2026. Change index: page 1 of 3 only; diffs unreviewed.",
        "September bonus evidence comes from the full notice embedded in the brief; archive index reviewed.",
        "USD uses platform accounting evidence. Browser-only policy recovery; authenticated eligibility and incorporated terms incompletely reviewed. Inventories/instructions omitted; live terms prevail. No authorization granted."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Nubank Brasil Managed Bug Bounty Program public brief",
          "url": "https://bugcrowd.com/engagements/nubank",
          "publisher": "Nubank Brasil / Bugcrowd",
          "retrieved_at": "2026-10-03T04:10:28Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "announcements",
          "title": "Nubank Brasil Managed Bug Bounty Program announcement archive",
          "url": "https://bugcrowd.com/engagements/nubank/announcements",
          "publisher": "Nubank Brasil / Bugcrowd",
          "retrieved_at": "2026-10-03T04:11:40Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "changelog",
          "title": "Nubank Brasil Managed Bug Bounty Program change index",
          "url": "https://bugcrowd.com/engagements/nubank/changelog",
          "publisher": "Nubank Brasil / Bugcrowd",
          "retrieved_at": "2026-10-03T04:12:14Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd Organization Accounting",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T04:09:31Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T04:10:21Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/nubank/changelog/90947bf4-bb77-470a-85a7-a71bc80b9ef2.json",
          "publisher": "Nubank Brasil",
          "retrieved_at": "2026-10-03T14:56:13Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Selected digital-banking mobile applications, first-party web services and investment services across distinct reward tiers.",
        "excluded_summary": "Unlisted properties, temporarily suspended community services, unsupported third-party findings, unrelated credential leaks and specified low-impact classes are excluded.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://bugcrowd.com/engagements/nubank"
        ],
        "verified_at": "2026-10-03T04:12:42Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:13Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "Nubank Android: Play Store",
            "asset_type": "android",
            "location": "https://play.google.com/store/apps/details?id=com.nu.production&hl=pt_BR&gl=US&pli=1",
            "group": "Core Assets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Nubank iOS App",
            "asset_type": "ios",
            "location": "https://apps.apple.com/br/app/nubank-conta-e-cart%C3%A3o/id814456780",
            "group": "Core Assets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "prod-*.nubank.com.br",
            "asset_type": "api",
            "location": null,
            "group": "Core Assets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "prod-*.nu.com.mx",
            "asset_type": "api",
            "location": null,
            "group": "Core Assets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "prod-*.nu.com.co",
            "asset_type": "api",
            "location": null,
            "group": "Core Assets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.nubank.com.br",
            "asset_type": "other",
            "location": "https://nubank.com.br/",
            "group": "Primary Assets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.nu.com.mx",
            "asset_type": "other",
            "location": "https://nubank.com.mx",
            "group": "Primary Assets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.nu.com.co",
            "asset_type": "other",
            "location": "https://nubank.com.co",
            "group": "Primary Assets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.nuinvest.com.br",
            "asset_type": "website",
            "location": "https://www.nuinvest.com.br/",
            "group": "Supplementary Assets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "*.nuinternational.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.nat-a.nubank.com.br",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "international.nubank.com.br",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "NuCommunity endpoints (BR, MX, CO)",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "nvidia-public-bug-bounty",
      "name": "NVIDIA Public Bug Bounty",
      "operator": "NVIDIA",
      "platform": "Intigriti",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://app.intigriti.com/programs/nvidia/nvidiapublicbugbounty",
      "policy_url": "https://app.intigriti.com/programs/nvidia/nvidiapublicbugbounty",
      "announcement_urls": [],
      "change_log_url": null,
      "last_verified_at": "2026-10-02T23:00:00Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Advertised tiers show $150–$5,000, $250–$10,000 and $300–$15,000. Critical and exceptional bands have equal ceilings. Dollar denomination is not explicitly established; normalized values remain null. These are policy figures, not individual awards.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "An Intigriti account is required. Sanctions restrictions apply. Platform terms require adulthood, or age 16 with guardian permission; rewards require first reporting, company validation, identity checks and compliance.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Scope covers selected Container Toolkit and CUDA Toolkit components, emphasizing real privilege-boundary impact. Unreleased Container Toolkit builds, theoretical findings and defects lacking security impact are excluded. Denial-of-service, brute force, social engineering and physical intrusion are excluded. Disclosure requires written consent.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "The logged-out page invites account-based submissions but provides no explicit current open/paused label. Acceptance is not inferred from page visibility or activity.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "The reviewed page does not establish the dollar denomination or a policy-wide revision date.",
        "The July 1, 2025 date applies only to a category-tier rule, not the entire policy.",
        "Logged-in submission eligibility and expanded safe-harbor terms were not verified. Live terms prevail; this summary grants no testing permission."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "NVIDIA Public Bug Bounty program policy",
          "url": "https://app.intigriti.com/programs/nvidia/nvidiapublicbugbounty",
          "publisher": "NVIDIA / Intigriti",
          "retrieved_at": "2026-10-02T23:00:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-02T23:00:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/nvidia/nvidiapublicbugbounty/detail",
          "publisher": "NVIDIA",
          "retrieved_at": "2026-10-03T14:56:15Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:15Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "new CDI-based architecture",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "All Other NVIDIA Container Toolkit Assets",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "libNVVM API",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Nsight Systems",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "NVIDIA Nsight Developer Tools",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "NVRTC library",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "CUDA Libraries",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "NVCC",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "nvJitLink APIs",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "CUDA Runtime APIs",
            "asset_type": "URL",
            "location": "http://CUDA Runtime APIs",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "CUDA Driver APIs",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "nxtport-vulnerability-disclosure",
      "name": "NxtPort Vulnerability Disclosure Program",
      "operator": "NxtPort",
      "platform": "Intigriti",
      "program_type": {
        "value": "vulnerability_disclosure",
        "summary": "Explicit no-bounty VDP; a discretionary EUR 25 delayed-validation bonus is exceptional.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://app.intigriti.com/programs/portofantwerp/nxtportvdp",
      "policy_url": "https://app.intigriti.com/programs/portofantwerp/nxtportvdp",
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "The conditional delay bonus is not a bounty schedule; currency/bounds remain null. Generic FAQ rewards are not guaranteed.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Intigriti accounts and researcher identification are required. Platform adulthood/guardian-approved age-16 and legal/employer conditions apply. Internally known findings may be duplicates.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "User-data access/alteration, operational disruption, harmful automation, social engineering, physical intrusion and denial-of-service are prohibited. Accidental sensitive-data exposure requires stopping, reporting and no retention. Confidentiality and conditional safe harbor apply.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Visible policies and login invitations do not verify acceptance.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T03:41:28Z",
      "limitations": [
        "No dedicated announcement/change-log or complete policy history verified.",
        "Logged-out review; authenticated eligibility and open/paused status unverified.",
        "High-level context omits asset inventories and testing instructions. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "NxtPort Vulnerability Disclosure Program policy",
          "url": "https://app.intigriti.com/programs/portofantwerp/nxtportvdp",
          "publisher": "NxtPort / Intigriti",
          "retrieved_at": "2026-10-03T03:38:48Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T01:50:12Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/portofantwerp/nxtportvdp/detail",
          "publisher": "NxtPort",
          "retrieved_at": "2026-10-03T14:56:16Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Designated digital port-community systems, applications and APIs, addressing service/data confidentiality, integrity and availability, including identity, tenant separation and dependency-security categories within the listed environment.",
        "excluded_summary": "Unlisted environments; low-impact configuration observations, unsupported software, theoretical claims and cases dependent on compromised accounts, physical access or interception. The policy excludes specified account/session, enumeration and rate-limiting report classes.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/portofantwerp/nxtportvdp"
        ],
        "verified_at": "2026-10-03T03:41:28Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:16Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "*.nxtport.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "No bounty",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "okta-bug-bounty",
      "name": "Okta Bug Bounty",
      "operator": "Okta",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/okta",
      "policy_url": "https://bugcrowd.com/engagements/okta",
      "announcement_urls": [],
      "change_log_url": null,
      "last_verified_at": "2026-10-02T23:00:00Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "rewards": {
        "currency": "USD",
        "minimum": 100,
        "maximum": 75000,
        "basis": "advertised_not_individual_award",
        "summary": "Ordinary product/severity schedules advertise $100–$75,000, with discretionary awards. A displayed October 7, 2025 notice advertises a limited-time bonus up to $500,000; its current applicability was not established and is excluded from the ordinary maximum. No individual award is claimed.",
        "source_ids": [
          "policy",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "A Bugcrowd account and designated researcher environments are required. Employees and relatives are excluded. Platform reward eligibility includes first valid reporting and applicable adulthood requirements. Supplemental terms impose legal and sanctions eligibility.",
        "source_ids": [
          "policy",
          "platform-terms",
          "supplemental-terms"
        ]
      },
      "restrictions": {
        "summary": "Selected identity, device and access-management products are covered. Okta Classic and Okta Personal are marked out of scope. No automated scanners, denial-of-service, customer-instance access, customer-data effects, social engineering or post-compromise pivoting. Reports need meaningful human analysis. Disclosure needs written approval.",
        "source_ids": [
          "policy",
          "supplemental-terms"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The official brief displays In progress, an ongoing period and a Submit report link. This does not establish any particular researcher’s eligibility.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "Brief displays May 22, 2026 as its update date. Older embedded announcements are not proof of current scope or bonus eligibility.",
        "USD normalization uses Bugcrowd accounting documentation; the brief itself displays dollar signs.",
        "The linked primary Vulnerability Disclosure Policy PDF could not be retrieved by the text tool. Supplemental terms were read and display July 22, 2019. Review is not a complete legal-terms audit.",
        "No authenticated submission was attempted. Product-specific setup details and asset inventories are deliberately omitted; live terms prevail.",
        "Linked announcement and change-log archives were not separately read; announcement facts above come from notices displayed within the reviewed brief."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Okta public program brief",
          "url": "https://bugcrowd.com/engagements/okta",
          "publisher": "Okta / Bugcrowd",
          "retrieved_at": "2026-10-02T23:00:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd Organization Accounting",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-02T23:00:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-02T23:00:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "supplemental-terms",
          "title": "Okta Vulnerability Disclosure Policy Supplemental Terms",
          "url": "https://www.okta.com/sites/default/files/VDP_Supplemental_Terms.pdf",
          "publisher": "Okta",
          "retrieved_at": "2026-10-02T23:00:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/okta/changelog/d4dc2398-db8d-4b89-9f7f-0aae75251307.json",
          "publisher": "Okta",
          "retrieved_at": "2026-10-03T14:56:17Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:17Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "bugcrowd-pam-###.oktapreview.com",
            "asset_type": "website",
            "location": null,
            "group": "Okta Privileged Access",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "bugcrowd-pam-###.pam.oktapreview.com",
            "asset_type": "website",
            "location": null,
            "group": "Okta Privileged Access",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://bugcrowd-pam-###.workflows.oktapreview.com",
            "asset_type": "website",
            "location": null,
            "group": "Okta Workflows",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Desktop MFA for Windows",
            "asset_type": "other",
            "location": null,
            "group": "Okta Device Access",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Desktop MFA for macOS",
            "asset_type": "other",
            "location": null,
            "group": "Okta Device Access",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Password Sync for macOS",
            "asset_type": "other",
            "location": null,
            "group": "Okta Device Access",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "support.okta.com",
            "asset_type": "website",
            "location": "https://support.okta.com",
            "group": "Okta Support Portal (support.okta.com)",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://bugcrowd-pam-###.at.oktapreview.com",
            "asset_type": "website",
            "location": null,
            "group": "AtSpoke (Okta Access Requests) (New)",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://bugcrowd-pam-###.oktapreview.com",
            "asset_type": "website",
            "location": null,
            "group": "Okta (OIE) In-Scope Targets (New)",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Okta Verify Fastpass",
            "asset_type": "other",
            "location": "https://www.okta.com/fastpass/",
            "group": "Okta (OIE) In-Scope Targets (New)",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://bugcrowd-pam-###-admin.oktapreview.com",
            "asset_type": "website",
            "location": null,
            "group": "Okta (OIE) In-Scope Targets (New)",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Advanced Server Access (ASA) / (ScaleFT)",
            "asset_type": "website",
            "location": "https://www.okta.com/products/advanced-server-access/",
            "group": "Advanced Server Access",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "http://app.scaleft.com/",
            "asset_type": "website",
            "location": null,
            "group": "Advanced Server Access",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Advanced Server Access Client / Agents",
            "asset_type": "other",
            "location": "https://help.okta.com/asa/en-us/Content/Topics/Adv_Server_Access/docs/client.htm",
            "group": "Advanced Server Access",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Okta Verify (iOS)",
            "asset_type": "ios",
            "location": "https://apps.apple.com/us/app/okta-verify/id490179405",
            "group": "Other In-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Okta Verify (Android)",
            "asset_type": "android",
            "location": "https://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=US",
            "group": "Other In-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Okta Verify (Mac OS)",
            "asset_type": "other",
            "location": "https://apps.apple.com/us/app/okta-verify/id490179405",
            "group": "Other In-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Okta Verify (Windows)",
            "asset_type": "other",
            "location": null,
            "group": "Other In-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Okta On-Prem Agents ( AD, LDAP, RDP, IWA )",
            "asset_type": "other",
            "location": null,
            "group": "Other In-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Okta Agent Windows",
            "asset_type": "other",
            "location": "https://help.okta.com/en/prod/Content/Topics/Adv_Server_Access/docs/sftd-windows.htm",
            "group": "Other In-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Okta Browser Plugin (IE / Firefox / Chrome)",
            "asset_type": "other",
            "location": "https://help.okta.com/en/prod/Content/Topics/Settings/download-browser-plugin.htm",
            "group": "Other In-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "personal.trexcloud.com",
            "asset_type": "website",
            "location": null,
            "group": "Okta Personal",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "bugcrowd-%username%-1.oktapreview.com",
            "asset_type": "website",
            "location": null,
            "group": "Okta (Classic) In-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "bugcrowd-%username%-2.oktapreview.com",
            "asset_type": "website",
            "location": null,
            "group": "Okta (Classic) In-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.okta.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.trexcloud.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "login.okta.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "pages.okta.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "developer.okta.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "trust.okta.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.okta.com (static site)",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://scaleft.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://app.scaleft.com/p/signup",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://github.com/oktadev",
            "asset_type": "website",
            "location": "https://github.com/oktadev",
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Backend Okta non-app infrastructure",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Network layer issues",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "AtSpoke - Okta Workflows actions in access requests",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "AtSpoke - Entitlement bundles as a resource in access requests",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Anything not explicitly called out above as in-scope",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "onetrust-bug-bounty",
      "name": "OneTrust Bug Bounty",
      "operator": "OneTrust",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The official brief advertises monetary bounties.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/onetrust",
      "policy_url": "https://bugcrowd.com/engagements/onetrust",
      "announcement_urls": [
        "https://bugcrowd.com/engagements/onetrust/announcements"
      ],
      "change_log_url": "https://bugcrowd.com/engagements/onetrust/changelog",
      "rewards": {
        "currency": "USD",
        "minimum": 300,
        "maximum": 6500,
        "basis": "advertised_not_individual_award",
        "summary": "Advertised bands span USD 300–6,500; CVSS, likelihood and impact influence rewards. Downgrades allow appeal; duplicate causes do not receive multiple awards.",
        "source_ids": [
          "policy",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "Current employees, those employed within 12 months, customers and customer-engaged testing companies are excluded. Platform first-valid-report rules apply; monetary compensation requires age 18 or the applicable age of majority.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Use assigned or self-created accounts in the designated staging environment. Avoid shared-setting changes and disruption. Social engineering is prohibited. Public disclosure is prohibited; safe harbor is conditional.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The official brief explicitly displays In progress and an ongoing period.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T04:12:42Z",
      "limitations": [
        "Brief revision: December 22, 2025; newer announcements exist. Change index: page 1 of 2; diffs unreviewed.",
        "April 21, 2026 exposure notice opened separately. No broader active-testing permission is inferred.",
        "USD uses platform accounting evidence. Browser-only recovery; attachment, authenticated credential access and complete legal terms unreviewed. Inventories/instructions omitted; live terms prevail. No authorization granted."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "OneTrust Bug Bounty public brief",
          "url": "https://bugcrowd.com/engagements/onetrust",
          "publisher": "OneTrust / Bugcrowd",
          "retrieved_at": "2026-10-03T04:10:50Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "announcements",
          "title": "OneTrust Bug Bounty announcement archive",
          "url": "https://bugcrowd.com/engagements/onetrust/announcements",
          "publisher": "OneTrust / Bugcrowd",
          "retrieved_at": "2026-10-03T04:11:40Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "changelog",
          "title": "OneTrust Bug Bounty change index",
          "url": "https://bugcrowd.com/engagements/onetrust/changelog",
          "publisher": "OneTrust / Bugcrowd",
          "retrieved_at": "2026-10-03T04:12:14Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd Organization Accounting",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T04:09:31Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T04:10:21Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/onetrust/changelog/33280231-4d3c-4ce3-9c8f-8d8ee98aeec7.json",
          "publisher": "OneTrust",
          "retrieved_at": "2026-10-03T14:56:19Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Designated staging application, including privacy-management workflows and integrations; an April 2026 notice adds qualifying public credential/confidential-information exposure.",
        "excluded_summary": "Other environments, authorization findings without full administrator escalation and specified low-impact classes are excluded. Leak-related awards remain discretionary under older brief wording.",
        "source_ids": [
          "policy",
          "announcements"
        ],
        "policy_urls": [
          "https://bugcrowd.com/engagements/onetrust",
          "https://bugcrowd.com/engagements/onetrust/announcements"
        ],
        "verified_at": "2026-10-03T04:12:42Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:19Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "https://pentest-app.onetrust.com/",
            "asset_type": "website",
            "location": "https://pentest-app.onetrust.com/",
            "group": "In-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "https://*.onetrust.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://store.onetrust.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.convercent.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.dataguidance.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://app.vendorpedia.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.preferencechoice.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.redacted.ai",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.sharedassessments.org",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://developer.onetrust.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://my.onetrust.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.vendorpedia.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.onetrustgrc.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.cookiepro.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://tv.onetrust.com/",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.cookielaw.org",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.onetrustpro.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.privacyconnect.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.onetrust.de",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.onetrust.se",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.onetrust.es",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.onetrust.fr",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.onetrust.it",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.privacytech.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.privacypedia.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.esgiq.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://*.trustweek2021.com",
            "asset_type": "website",
            "location": null,
            "group": "Out-of-Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "openai-security-bug-bounty",
      "name": "OpenAI Security Bug Bounty",
      "operator": "OpenAI",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy",
          "updates"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/openai",
      "policy_url": "https://bugcrowd.com/engagements/openai",
      "announcement_urls": [
        "https://bugcrowd.com/engagements/openai/announcements"
      ],
      "change_log_url": "https://bugcrowd.com/engagements/openai/announcements",
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Advertised maximum $100,000 for exceptional critical findings; category-dependent schedules include amounts from $50. The historical $20,000 ceiling is outdated.",
        "source_ids": [
          "policy",
          "updates"
        ]
      },
      "eligibility": {
        "summary": "First qualifying previously unknown issue with meaningful security impact; Bugcrowd account, age-of-majority and payment eligibility requirements apply.",
        "source_ids": [
          "policy",
          "terms"
        ]
      },
      "restrictions": {
        "summary": "Use only owned or expressly authorized accounts/data; avoid disruption, destruction, social engineering and unrelated third parties. Model-only content issues and intended sandbox behavior generally do not qualify. Disclosure requires permission.",
        "source_ids": [
          "policy",
          "terms"
        ]
      },
      "last_verified_at": "2026-10-02T21:01:00Z",
      "limitations": [
        "Live policy was reviewed in a browser because text retrieval omitted its dynamic content.",
        "The page displayed active status and an August 19, 2026 update; this is not proof of its full change history.",
        "Reward ranges vary by category and remain discretionary; consult the live policy.",
        "Currency is displayed as a dollar sign; linked standard terms mention USD generally but program-specific denomination was not explicit. Normalized bounds remain null."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "OpenAI Security Bug Bounty",
          "url": "https://bugcrowd.com/engagements/openai",
          "publisher": "OpenAI / Bugcrowd",
          "retrieved_at": "2026-10-02T21:01:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "updates",
          "title": "OpenAI program announcements",
          "url": "https://bugcrowd.com/engagements/openai/announcements",
          "publisher": "OpenAI / Bugcrowd",
          "retrieved_at": "2026-10-02T21:01:00Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-02T21:01:00Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/openai/changelog/e76106d3-3796-492b-9997-569446b51b72.json",
          "publisher": "OpenAI",
          "retrieved_at": "2026-10-03T14:56:20Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "submission_status": {
        "value": "accepting_reports",
        "summary": "Program displayed active status at review; live terms and eligibility still apply.",
        "source_ids": [
          "policy"
        ]
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:20Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "api.openai.com",
            "asset_type": "api",
            "location": "https://api.openai.com",
            "group": "API Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "ChatGPT",
            "asset_type": "website",
            "location": "https://chat.openai.com",
            "group": "ChatGPT",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "ChatGPT Plugins",
            "asset_type": "api",
            "location": "https://chat.openai.com",
            "group": "ChatGPT",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Third Party Targets",
            "asset_type": "website",
            "location": null,
            "group": "Third Party Corporate Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "OpenAI API Keys",
            "asset_type": "api",
            "location": null,
            "group": "OpenAI API Keys",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://openai.org",
            "asset_type": "website",
            "location": "https://*.openai.org",
            "group": "OpenAI Research Org",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.openai.org",
            "asset_type": "api",
            "location": "https://*.openai.org",
            "group": "OpenAI Research Org",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "openai.com",
            "asset_type": "website",
            "location": "https://openai.com/",
            "group": "Other OpenAI Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.openai.com",
            "asset_type": "other",
            "location": null,
            "group": "Other OpenAI Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Developer Platform Playground",
            "asset_type": "website",
            "location": "https://platform.openai.com/playground",
            "group": "Other OpenAI Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Other",
            "asset_type": "other",
            "location": null,
            "group": "Other OpenAI Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Codex Desktop",
            "asset_type": "other",
            "location": null,
            "group": "Codex",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "proton-bug-bounty",
      "name": "Proton Bug Bounty",
      "operator": "Proton AG",
      "platform": "Direct vendor program",
      "program_url": "https://proton.me/security/bug-bounty",
      "policy_url": "https://proton.me/security/bug-bounty",
      "announcement_urls": [],
      "change_log_url": null,
      "last_verified_at": "2026-10-03T03:20:30Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "rewards": {
        "currency": "USD",
        "minimum": 1000,
        "maximum": 100000,
        "basis": "advertised_not_individual_award",
        "summary": "Published paid bands start at USD 1,000; the ordinary critical band ends at USD 50,000, with an exceptional ceiling of USD 100,000. Low-severity rewards are discretionary and normally nonmonetary. These are advertised guidelines, not individual awards.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "First valid reports with concrete, reproducible security impact qualify after confirmation and deployment of a fix. Intended behavior and unsupported theoretical recommendations are excluded. Anonymous reporting is allowed; submissions must respect third-party intellectual property and grant Proton a broad report-use license.",
        "source_ids": [
          "policy",
          "disclosure"
        ]
      },
      "restrictions": {
        "summary": "Only explicitly included services qualify. No third-party, physical, social-engineering or disruptive activity, malware, data alteration, exfiltration or persistence. Stop and notify Proton upon finding a vulnerability or nonpublic-data exposure; purge retained nonpublic data when reporting. Disclosure normally waits 120 days after acknowledgment. Conditional safe harbor cannot bind third parties.",
        "source_ids": [
          "disclosure",
          "safe-harbor"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The disclosure policy explicitly states that reports are accepted by email. This is policy evidence, not a delivery or response test.",
        "source_ids": [
          "disclosure"
        ]
      },
      "limitations": [
        "The disclosure policy is dated July 30, 2025; safe harbor September 29, 2022. The bounty page shows no overall revision date.",
        "The numeric minimum is the lowest published paid tier, not a guaranteed payout floor; low-severity cases have no fixed monetary schedule.",
        "No program-specific age, residency or employee eligibility rule was established from these pages. No submission was made.",
        "Public policy review only. Asset inventories and operational instructions are omitted. Live terms prevail; this summary grants no authorization or legal protection."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Proton bug bounty program",
          "url": "https://proton.me/security/bug-bounty",
          "publisher": "Proton AG",
          "retrieved_at": "2026-10-03T03:20:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "disclosure",
          "title": "Proton vulnerability disclosure policy",
          "url": "https://proton.me/security/vulnerability-disclosure",
          "publisher": "Proton AG",
          "retrieved_at": "2026-10-03T03:20:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "safe-harbor",
          "title": "Proton legal safe harbor policy",
          "url": "https://proton.me/security/safe-harbor",
          "publisher": "Proton AG",
          "retrieved_at": "2026-10-03T02:12:34Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Proton vulnerability disclosure scope",
          "url": "https://proton.me/security/vulnerability-disclosure",
          "publisher": "Proton AG",
          "retrieved_at": "2026-10-03T15:03:35Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "program_type": {
        "value": "paid_bounty",
        "summary": "The official policy advertises monetary bounties for eligible reports.",
        "source_ids": [
          "policy"
        ]
      },
      "scope_context": {
        "included_summary": "Listed account, communications, storage, productivity, password-management, authentication, VPN, wallet, AI, aliasing and notes products; supported client variants differ.",
        "excluded_summary": "Unlisted services, outsourced support and commerce, and sandboxed-content scripting are excluded. Content injection requires significant risk; mobile-crash eligibility depends on operating-system and device recency.",
        "source_ids": [
          "disclosure"
        ],
        "policy_urls": [
          "https://proton.me/security/vulnerability-disclosure"
        ],
        "verified_at": "2026-10-03T03:20:30Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_policy_page",
        "verified_at": "2026-10-03T15:03:35Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "proton.me",
            "asset_type": "website",
            "location": null,
            "group": "Proton",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "account.proton.me",
            "asset_type": "web_app",
            "location": null,
            "group": "Proton",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "calendar.proton.me",
            "asset_type": "web_app",
            "location": null,
            "group": "Proton Calendar",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Calendar apps (Android, iOS/iPad)",
            "asset_type": "mobile_app",
            "location": null,
            "group": "Proton Calendar",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "drive.proton.me",
            "asset_type": "web_app",
            "location": null,
            "group": "Proton Drive",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Drive apps (Android, iOS/iPad beta, Windows)",
            "asset_type": "application",
            "location": null,
            "group": "Proton Drive",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "docs.proton.me",
            "asset_type": "web_app",
            "location": null,
            "group": "Proton Docs",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "mail.proton.me",
            "asset_type": "web_app",
            "location": null,
            "group": "Proton Mail",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "api.protonmail.ch",
            "asset_type": "web_app",
            "location": null,
            "group": "Proton Mail",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Mail mobile apps (Android, iOS/iPad)",
            "asset_type": "mobile_app",
            "location": null,
            "group": "Proton Mail",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Bridge (GNU/Linux, macOS, Windows)",
            "asset_type": "desktop_app",
            "location": null,
            "group": "Proton Mail",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Scribe",
            "asset_type": "product",
            "location": null,
            "group": "Proton Mail",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "pass.proton.me",
            "asset_type": "web_app",
            "location": null,
            "group": "Proton Pass",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Pass mobile apps (Android, iOS/iPad)",
            "asset_type": "mobile_app",
            "location": null,
            "group": "Proton Pass",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Pass desktop apps (Linux, macOS, Windows)",
            "asset_type": "desktop_app",
            "location": null,
            "group": "Proton Pass",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Pass extensions (Chrome, Firefox)",
            "asset_type": "browser_extension",
            "location": null,
            "group": "Proton Pass",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Authenticator mobile apps (Android, iOS/iPad)",
            "asset_type": "mobile_app",
            "location": null,
            "group": "Proton Authenticator",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Authenticator desktop apps (Linux, macOS, Windows)",
            "asset_type": "desktop_app",
            "location": null,
            "group": "Proton Authenticator",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "protonvpn.com",
            "asset_type": "website",
            "location": null,
            "group": "Proton VPN",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "account.protonvpn.com",
            "asset_type": "web_app",
            "location": null,
            "group": "Proton VPN",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "api.protonvpn.ch",
            "asset_type": "web_app",
            "location": null,
            "group": "Proton VPN",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton VPN apps (Android, iOS/iPad, Linux, macOS, Windows)",
            "asset_type": "application",
            "location": null,
            "group": "Proton VPN",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton VPN extensions (Android TV, Apple TV, Chrome, Chromebook, Firefox)",
            "asset_type": "browser_extension",
            "location": null,
            "group": "Proton VPN",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "wallet.proton.me",
            "asset_type": "web_app",
            "location": null,
            "group": "Proton Wallet",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Wallet apps (Android, iOS)",
            "asset_type": "mobile_app",
            "location": null,
            "group": "Proton Wallet",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "lumo.proton.me",
            "asset_type": "web_app",
            "location": null,
            "group": "Lumo by Proton",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Proton Lumo apps (Android, iOS)",
            "asset_type": "mobile_app",
            "location": null,
            "group": "Lumo by Proton",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "simplelogin.io",
            "asset_type": "website",
            "location": null,
            "group": "SimpleLogin",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "app.simplelogin.io",
            "asset_type": "web_app",
            "location": null,
            "group": "SimpleLogin",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "SimpleLogin mobile apps (Android, iOS)",
            "asset_type": "mobile_app",
            "location": null,
            "group": "SimpleLogin",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "SimpleLogin extensions (Chrome, Edge, Firefox, Safari)",
            "asset_type": "browser_extension",
            "location": null,
            "group": "SimpleLogin",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "standardnotes.com",
            "asset_type": "website",
            "location": null,
            "group": "Standard Notes",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "app.standardnotes.com",
            "asset_type": "web_app",
            "location": null,
            "group": "Standard Notes",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Standard Notes apps (Android, iOS/iPad, Linux, macOS, Windows)",
            "asset_type": "application",
            "location": null,
            "group": "Standard Notes",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "shop.proton.me",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "proton.me/support/contact",
            "asset_type": "website",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "protonmail.zendesk.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "support.protonmail.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "help.protonmail.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "status.proton.me",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "partners.proton.me",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "localize.proton.me",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Only services explicitly named in Proton's disclosure policy are included; the bounty page delegates scope to that policy.",
          "App/platform variants are grouped as the policy presents them. Third-party and unlisted services remain excluded."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "rapyd-bug-bounty",
      "name": "Rapyd Bug Bounty",
      "operator": "Rapyd",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The official brief advertises monetary bounties.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/rapyd",
      "policy_url": "https://bugcrowd.com/engagements/rapyd",
      "announcement_urls": [
        "https://bugcrowd.com/engagements/rapyd/announcements"
      ],
      "change_log_url": "https://bugcrowd.com/engagements/rapyd/changelog",
      "rewards": {
        "currency": "USD",
        "minimum": 100,
        "maximum": 7500,
        "basis": "advertised_not_individual_award",
        "summary": "Ordinary tiers advertise USD 100–7,500, 100–5,500 and 100–3,000. Impact-based increases and a minimum $500 payment-data bonus are separate; no combined ceiling established. The May–June 2026 SSO promotion expired.",
        "source_ids": [
          "policy",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "Researcher identification, program-compliant accounts and concrete evidence are required. Platform first-valid-report rules apply; monetary compensation requires age 18 or the applicable age of majority.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Owned accounts only. Stop on nonpublic-data access and delete retained information. No form automation, social engineering, disruption or third-party evidence hosting. Public disclosure is prohibited.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The official brief explicitly displays In progress and an ongoing period.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T04:15:59Z",
      "limitations": [
        "Brief revision: June 17, 2026. Change index: page 1 of 4; diffs unreviewed.",
        "Announcement index reviewed; recent notices read within the brief. Attachments, linked setup documentation and authenticated eligibility unreviewed.",
        "USD uses platform accounting evidence. Static text omitted the brief. Inventories/instructions omitted; live terms prevail. No authorization granted."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Rapyd Bug Bounty public brief",
          "url": "https://bugcrowd.com/engagements/rapyd",
          "publisher": "Rapyd / Bugcrowd",
          "retrieved_at": "2026-10-03T04:15:59Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "announcements",
          "title": "Rapyd Bug Bounty announcement archive",
          "url": "https://bugcrowd.com/engagements/rapyd/announcements",
          "publisher": "Rapyd / Bugcrowd",
          "retrieved_at": "2026-10-03T04:11:40Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "changelog",
          "title": "Rapyd Bug Bounty change index",
          "url": "https://bugcrowd.com/engagements/rapyd/changelog",
          "publisher": "Rapyd / Bugcrowd",
          "retrieved_at": "2026-10-03T04:12:14Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd Organization Accounting",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T04:09:31Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T04:10:21Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/rapyd/changelog/4fd154ee-8a7d-4d42-bab8-2ff1e017c1b2.json",
          "publisher": "Rapyd",
          "retrieved_at": "2026-10-03T14:56:21Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Selected payment APIs, merchant-management, identity-verification and checkout services; API coverage is restricted to sandbox environments.",
        "excluded_summary": "Unlisted/third-party services, known SSO findings, self-imposed identity-provider weaknesses and specified low-impact classes are excluded. Out-of-scope reports may be accepted without rewards.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://bugcrowd.com/engagements/rapyd"
        ],
        "verified_at": "2026-10-03T04:15:59Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:21Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "api.rapyd.net",
            "asset_type": "api",
            "location": null,
            "group": "Tier 3 In scope Premium",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "dashboard.rapyd.net",
            "asset_type": "website",
            "location": "https://dashboard.rapyd.net/",
            "group": "Tier 2 In scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "verify.rapyd.net",
            "asset_type": "website",
            "location": null,
            "group": "Tier 2 In scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "checkout.rapyd.net",
            "asset_type": "other",
            "location": null,
            "group": "Tier 2 In scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.rapyd.net",
            "asset_type": "website",
            "location": null,
            "group": "Tier 1 In scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.korta.is",
            "asset_type": "website",
            "location": null,
            "group": "Tier 1 In scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "jointhemoment.net",
            "asset_type": "website",
            "location": "https://jointhemoment.net/",
            "group": "Tier 1 In scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.rapyd.com",
            "asset_type": "other",
            "location": null,
            "group": "Tier 1 In scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.rapyd.org",
            "asset_type": "other",
            "location": null,
            "group": "Tier 1 In scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.kortathjonustan.is",
            "asset_type": "website",
            "location": null,
            "group": "Tier 1 In scope",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "community.rapyd.net",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "support.rapyd.net",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "docs.rapyd.net",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "sandbox.rapyd.net",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "3rd party services",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "ghost.rapyd.net",
            "asset_type": "other",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.neatcommerce.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.neattest.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.neat.com.hk",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.neat.hk",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.neat.wtf",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "platform": "Intigriti",
      "program_type": {
        "value": "vulnerability_disclosure",
        "summary": "The policy explicitly describes a disclosure program without monetary bounties.",
        "source_ids": [
          "policy"
        ]
      },
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "No monetary bounty schedule; currency and numeric bounds remain null.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Logged-out policy and login invitation do not independently establish current intake status.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T04:29:23Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "id": "spacelift-vulnerability-disclosure",
      "name": "Spacelift Vulnerability Disclosure Program",
      "operator": "Spacelift",
      "program_url": "https://app.intigriti.com/programs/spacelift/spaceliftvdp",
      "policy_url": "https://app.intigriti.com/programs/spacelift/spaceliftvdp",
      "eligibility": {
        "summary": "Platform membership and researcher-identified accounts are required; findings must be original and validated. Internally known findings count as duplicates. Platform eligibility requires age 18, or 16 with guardian permission, plus legal and employer authorization.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Disclosure needs written consent. Automation is bounded; disruption, social engineering, physical intrusion and brute force are prohibited.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "Policy acceptance language and recent activity do not verify the authenticated intake state.",
        "No announcement archive or complete revision history was established. Expanded safe-harbor terms and other incorporated documents remain unreviewed.",
        "Logged-out review; summaries omit inventories and procedures. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Spacelift Vulnerability Disclosure Program policy",
          "url": "https://app.intigriti.com/programs/spacelift/spaceliftvdp",
          "publisher": "Spacelift / Intigriti",
          "retrieved_at": "2026-10-03T04:28:45Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T04:29:02Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/spacelift/spaceliftvdp/detail",
          "publisher": "Spacelift",
          "retrieved_at": "2026-10-03T14:56:22Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "scope_context": {
        "included_summary": "Designated pre-production infrastructure-orchestration services, emphasizing tenant separation, execution isolation and delegated cloud-access boundaries.",
        "excluded_summary": "Production services, intended in-job code execution, same-account visibility, specified account-limit/session behavior, externally sourced credentials and unsupported-impact findings are excluded.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/spacelift/spaceliftvdp"
        ],
        "verified_at": "2026-10-03T04:29:23Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:22Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "*.app.spacelift.dev",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "app.spacelift.dev",
            "asset_type": "URL",
            "location": "http://app.spacelift.dev",
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "spacelift.dev",
            "asset_type": "URL",
            "location": "http://spacelift.dev",
            "group": "Tier 5",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "telegram-bug-bounty",
      "name": "Telegram Bug Bounty",
      "operator": "Telegram",
      "platform": "Direct vendor program",
      "program_url": "https://core.telegram.org/bug-bounty",
      "policy_url": "https://core.telegram.org/bug-bounty",
      "announcement_urls": [],
      "change_log_url": null,
      "last_verified_at": "2026-10-03T03:20:30Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The official policy explicitly offers monetary bounties for eligible reports.",
        "source_ids": [
          "policy"
        ]
      },
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Advertised awards range from $100 to $100,000 or more: application-level guidance reaches $10,000, while protocol-level awards may exceed $100,000. Validity and amounts remain discretionary. Dollar denomination is unverified, so normalized bounds remain null.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "First reports take precedence; duplicates do not qualify. Reports must be in English and produce a code or configuration change. Recipients bear taxes and fees. Unrelated third-party implementation faults are excluded.",
        "source_ids": [
          "policy"
        ]
      },
      "restrictions": {
        "summary": "No unlawful activity, privacy harm, disruption, physical access, spam or social engineering. Premature public or third-party disclosure forfeits eligibility. Unsupported scanner output and compromised-device scenarios generally do not qualify. Legal protection depends on following the rules.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The policy explicitly describes continuous operation since 2014 and direct email submissions. It expressly disclaims third-party bounty-platform participation.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "No revision date, dedicated change log, age or residency criterion was established. Intake was not tested.",
        "Advertised figures are not individual awards. Scope inventories and testing instructions are omitted; full live terms prevail."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Telegram Bug Bounty Program",
          "url": "https://core.telegram.org/bug-bounty",
          "publisher": "Telegram",
          "retrieved_at": "2026-10-03T03:20:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Telegram Bug Bounty Program",
          "url": "https://core.telegram.org/bug-bounty",
          "publisher": "Telegram",
          "retrieved_at": "2026-10-03T15:03:35Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "scope_context": {
        "included_summary": "Telegram-operated apps, services and protocols handling private data; third-party clients and bots qualify only for Telegram-side faults.",
        "excluded_summary": "Third-party implementation errors and non-security defects are excluded; lower-impact findings may remain eligible.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://core.telegram.org/bug-bounty"
        ],
        "verified_at": "2026-10-03T03:20:30Z"
      },
      "asset_scope": {
        "capture_status": "policy_defined",
        "collection_method": "official_policy_page",
        "verified_at": "2026-10-03T15:03:35Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "telegram.org",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.telegram.org",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "t.me",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.t.me",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "tg.dev",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.tg.dev",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "telegram.me",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.telegram.me",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.telesco.pe",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.stel.com",
            "asset_type": "domain_pattern",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "contest.com",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "quiz.directory",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "telegra.ph",
            "asset_type": "domain",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Official Telegram applications",
            "asset_type": "application",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Telegram-operated apps that handle or store private user data."
          },
          {
            "name": "MTProto 2.0",
            "asset_type": "protocol",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Realistic unauthorized user-data access impact is required."
          },
          {
            "name": "Telegram-operated services and servers handling private user data",
            "asset_type": "policy_category",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "No finite service or server inventory is published."
          }
        ],
        "out_of_scope": [
          {
            "name": "Third-party domains integrating Telegram",
            "asset_type": "policy_category",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Third-party apps and bots",
            "asset_type": "policy_category",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "note": "Their own implementation faults are excluded; Telegram-side flaws can qualify."
          }
        ],
        "limitations": [
          "The listed domains are examples of permitted Telegram scope, subject to ownership and private-data impact; the app/service categories are broader than a finite asset list."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "platform": "Intigriti",
      "program_type": {
        "value": "vulnerability_disclosure",
        "summary": "The policy explicitly describes a disclosure program without monetary bounties.",
        "source_ids": [
          "policy"
        ]
      },
      "announcement_urls": [],
      "change_log_url": null,
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "No monetary bounty schedule; currency and numeric bounds remain null.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Logged-out policy and login invitation do not independently establish current intake status.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T04:29:23Z",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "id": "truelayer-vulnerability-disclosure",
      "name": "TrueLayer Vulnerability Disclosure Program",
      "operator": "TrueLayer",
      "program_url": "https://app.intigriti.com/programs/truelayer/truelayervdp",
      "policy_url": "https://app.intigriti.com/programs/truelayer/truelayervdp",
      "eligibility": {
        "summary": "Researcher-identified platform accounts are required. Certain production access requires customer identity checks; credentials for the associated payment-service portfolio are unavailable. Platform eligibility requires age 18, or 16 with guardian permission, plus legal and employer authorization.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Disclosure needs written consent. Automation is bounded; disruption, social engineering, physical intrusion and brute force are prohibited.",
        "source_ids": [
          "policy"
        ]
      },
      "limitations": [
        "The separate paid program does not change this VDP’s explicit no-reward policy.",
        "Anonymous-reporting language coexists with platform-account requirements; anonymous intake was not verified.",
        "No revision archive, expanded safe-harbor text or complete incorporated-document review was established.",
        "Logged-out review; summaries omit inventories and procedures. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "TrueLayer Vulnerability Disclosure Program policy",
          "url": "https://app.intigriti.com/programs/truelayer/truelayervdp",
          "publisher": "TrueLayer / Intigriti",
          "retrieved_at": "2026-10-03T04:29:06Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T04:29:02Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/truelayer/truelayervdp/detail",
          "publisher": "TrueLayer",
          "retrieved_at": "2026-10-03T14:56:24Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "scope_context": {
        "included_summary": "Designated open-banking, payment and associated digital services, with sandbox use encouraged and customer-data separation emphasized.",
        "excluded_summary": "Third-party services and contact forms are excluded, except operator-controlled misconfigurations subject to third-party terms. Low-impact application/mobile claims and unsupported scenarios are excluded.",
        "source_ids": [
          "policy"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/truelayer/truelayervdp"
        ],
        "verified_at": "2026-10-03T04:29:23Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:24Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "*.truelayer.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 1",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.zimpler.net",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.sandbox.zimpler.net",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.staging.zimpler.net",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.truelayer-sandbox.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "checkout-playground.zimpler.com",
            "asset_type": "URL",
            "location": "http://checkout-playground.zimpler.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "devdocs.zimpler.com",
            "asset_type": "URL",
            "location": "http://devdocs.zimpler.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "identify.zimpler.com",
            "asset_type": "URL",
            "location": "http://identify.zimpler.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "okta-oauth2.zimpler.com",
            "asset_type": "URL",
            "location": "http://okta-oauth2.zimpler.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "swish-playground.zimpler.com",
            "asset_type": "URL",
            "location": "http://swish-playground.zimpler.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "zimpler-merchant.zimpler.com",
            "asset_type": "URL",
            "location": "http://zimpler-merchant.zimpler.com",
            "group": "Tier 3",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "*.zimpler.com",
            "asset_type": "Wildcard",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "trusted-firmware-bug-bounty",
      "name": "Trusted Firmware Bug Bounty",
      "operator": "Arm",
      "platform": "Intigriti",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The policy advertises discretionary monetary bounties for eligible firmware reports.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://app.intigriti.com/programs/arm/trustedfirmware",
      "policy_url": "https://app.intigriti.com/programs/arm/trustedfirmware",
      "announcement_urls": [
        "https://app.intigriti.com/programs/arm/trustedfirmware/updates"
      ],
      "change_log_url": "https://app.intigriti.com/programs/arm/trustedfirmware/updates",
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Advertised severity amounts: $1,000, $3,000, $10,000 and $20,000. Certain privileged-component findings are capped at Low. Dollar denomination is unverified; normalized currency and bounds remain null.",
        "source_ids": [
          "policy"
        ]
      },
      "eligibility": {
        "summary": "Participants must be 18 or older and legally reward-eligible. Sanctions restrictions and 12-month employment/immediate-family exclusions involving Trusted Firmware member companies apply. Platform first-valid-report and identity-check requirements apply.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Reports need human-validated, realistic security impact. Social engineering, physical intrusion and DDoS are prohibited; disclosure requires written consent. Conditional protections cannot authorize third-party systems.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "unknown",
        "summary": "Logged-out policy and login invitation do not independently verify current acceptance.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T03:58:15Z",
      "limitations": [
        "Two July 2026 notices were reviewed; complete historical coverage was not established.",
        "Platform euro settlement does not establish the advertised dollar denomination.",
        "Logged-out text review; authenticated eligibility and incorporated documents were not exhaustively checked.",
        "High-level summaries omit inventories and testing instructions. Live terms prevail; this record grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Trusted Firmware Bug Bounty policy",
          "url": "https://app.intigriti.com/programs/arm/trustedfirmware",
          "publisher": "Arm / Intigriti",
          "retrieved_at": "2026-10-03T03:56:43Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Intigriti Researcher Terms & Conditions",
          "url": "https://kb.intigriti.com/en/articles/5466165-researcher-terms-conditions",
          "publisher": "Intigriti",
          "retrieved_at": "2026-10-03T03:57:30Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "updates",
          "title": "Trusted Firmware program updates: July 17 and July 28, 2026",
          "url": "https://app.intigriti.com/programs/arm/trustedfirmware/updates",
          "publisher": "Arm / Intigriti",
          "retrieved_at": "2026-10-03T03:57:17Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Intigriti asset table",
          "url": "https://app.intigriti.com/programs/arm/trustedfirmware/detail",
          "publisher": "Arm",
          "retrieved_at": "2026-10-03T14:56:26Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "scope_context": {
        "included_summary": "Selected production trusted-firmware, trusted-execution and cryptographic code on main or supported LTS branches, within project threat models.",
        "excluded_summary": "Unlisted projects, web infrastructure, nonproduction code, non-Arm platform code, kernel-driver findings and unofficial modifications are excluded. The July 28, 2026 update narrowed cryptographic coverage to a designated submodule.",
        "source_ids": [
          "policy",
          "updates"
        ],
        "policy_urls": [
          "https://app.intigriti.com/programs/arm/trustedfirmware",
          "https://app.intigriti.com/programs/arm/trustedfirmware/updates"
        ],
        "verified_at": "2026-10-03T03:58:15Z"
      },
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:26Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "TrustedFirmware-A (TF-A)",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "TrustedFirmware-M (TF-M)",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "TF-PSA-Crypto",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "OP-TEE",
            "asset_type": "Other",
            "location": null,
            "group": "Tier 2",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published asset table rows were captured; program detail and out-of-scope prose may add restrictions. An empty out-of-scope table is not unrestricted scope."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "vercel-bug-bounty",
      "name": "Vercel Bug Bounty",
      "operator": "Vercel",
      "platform": "HackerOne",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy",
          "rewards"
        ]
      },
      "program_url": "https://hackerone.com/vercel?type=team",
      "policy_url": "https://hackerone.com/vercel?type=team",
      "announcement_urls": [
        "https://hackerone.com/vercel/updates"
      ],
      "change_log_url": "https://hackerone.com/vercel/updates",
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "last_verified_at": "2026-10-03T01:50:37Z",
      "rewards": {
        "currency": null,
        "minimum": null,
        "maximum": null,
        "basis": "advertised_not_individual_award",
        "summary": "Paid bounty. Platform bands: Low $50–$500, Medium $750–$1,750, High $2,000–$3,000, Critical $3,500–$5,500. Open-source Tier 1: $200–$500, $550–$1,000, $1,250–$5,000, $5,250–$10,000; Tier 2: $50–$200, $250–$500, $750–$2,500, $2,750–$5,000. Severity and category determine the band; bonuses and awards remain discretionary. Figures are advertisements, not individual awards.",
        "source_ids": [
          "policy",
          "rewards"
        ]
      },
      "eligibility": {
        "summary": "First reproducible qualifying report receives precedence; shared root causes receive one award. Human-validated evidence and designated researcher identification are required. Past or present employees, contractors, sponsored-project maintainers/contributors, immediate employee relatives, relevant paid-engagement participants and assigned HackerOne staff are excluded.",
        "source_ids": [
          "policy"
        ]
      },
      "restrictions": {
        "summary": "Limit activity to owned or expressly authorized accounts and data. Open-source findings must be reproduced locally, with no active production testing. No social engineering, disruption, persistence or retention of others’ sensitive data. Customer applications, unrelated third parties, examples, deprecated products and unsupported-impact reports are excluded. Publication requires written consent; confidentiality duties continue two years after disclosure.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The September 21, 2026 announcement explicitly opens this consolidated program to the security community. It says the separate Vercel Open Source program closed to new submissions and moved its coverage here; that predecessor is not treated as this identity.",
        "source_ids": [
          "updates"
        ]
      },
      "limitations": [
        "Policy displays September 22, 2026; reward page displays September 21, 2026. These are visible update dates, not a complete revision audit.",
        "Reviewed pages show dollar signs without an explicit ISO denomination; normalized currency and bounds remain null.",
        "Policy-version and reward-version archives, linked attachments, repository-specific policies and authenticated submission flow were not reviewed. The predecessor program URL was not independently verified.",
        "Summaries deliberately omit asset inventories and procedural testing instructions. They grant no authorization; full live terms and category-specific exclusions prevail."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Vercel | Bounty Policy | HackerOne",
          "url": "https://hackerone.com/vercel?type=team",
          "publisher": "Vercel / HackerOne",
          "retrieved_at": "2026-10-03T01:49:43Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "rewards",
          "title": "Vercel scope and advertised rewards",
          "url": "https://hackerone.com/vercel/policy_scopes",
          "publisher": "Vercel / HackerOne",
          "retrieved_at": "2026-10-03T01:50:37Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "updates",
          "title": "Vercel public program updates",
          "url": "https://hackerone.com/vercel/updates",
          "publisher": "Vercel / HackerOne",
          "retrieved_at": "2026-10-03T01:50:10Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published HackerOne structured scope",
          "url": "https://hackerone.com/vercel/policy_scopes",
          "publisher": "Vercel",
          "retrieved_at": "2026-10-03T14:59:15Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:59:15Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "*.vercel.live",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "*.vercel.com",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "vercel.app",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "vercel.com",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "v0.dev",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "v0.app",
            "asset_type": "URL",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/nitrojs/nitro",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/nuxt/nuxt",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/sveltejs/svelte",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel-labs/agent-skills",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel-labs/skills",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/ai",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/async-sema",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/chat",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/flags",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/next.js",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/swr",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/turborepo",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/vercel",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/workflow",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/eve",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "https://github.com/vercel/ms",
            "asset_type": "SOURCE_CODE",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          },
          {
            "name": "Vercel sandbox",
            "asset_type": "OTHER",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": true
          }
        ],
        "out_of_scope": [
          {
            "name": "*.vercel.app",
            "asset_type": "WILDCARD",
            "location": null,
            "group": null,
            "source_ids": [
              "assets-scope-2026-10-03"
            ],
            "bounty_eligible": false
          }
        ],
        "limitations": [
          "Published structured-scope rows were captured. Submission eligibility and bounty eligibility differ; program policy text may add restrictions."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "vinted-bug-bounty",
      "name": "Vinted Bug Bounty",
      "operator": "Vinted",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/vinted-uab-mbb",
      "policy_url": "https://bugcrowd.com/engagements/vinted-uab-mbb",
      "announcement_urls": [
        "https://bugcrowd.com/engagements/vinted-uab-mbb/announcements"
      ],
      "change_log_url": "https://bugcrowd.com/engagements/vinted-uab-mbb/changelog",
      "rewards": {
        "currency": "USD",
        "minimum": 75,
        "maximum": 4000,
        "basis": "advertised_not_individual_award",
        "summary": "Primary-category guidelines advertise $75–$4,000; secondary-category guidelines $100–$800. Business impact can change priority or payout, with an appeal route. These are advertised schedules, not awards.",
        "source_ids": [
          "policy",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "Public participation without invitation began September 30, 2026. Researcher-identified accounts, original human analysis and reproducible impact are required. Confirmed deletion of acquired member data is a reward condition. Platform first-valid-report rules apply; monetary compensation requires age 18 or the applicable age of majority.",
        "source_ids": [
          "policy",
          "announcements",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Only expressly listed properties qualify. Protect production stability and use owned accounts and transactions; interaction with real members is prohibited. No high-volume scanning, disruption, social engineering or data enumeration. Low-impact and scanner-only findings are excluded. Disclosure requires permission; safe harbor is conditional.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The official brief explicitly displays In progress and an ongoing period, with a submission link. Individual eligibility remains subject to live terms.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T01:52:33Z",
      "limitations": [
        "Brief and change index show September 30, 2026 as the latest revision. The sole announcement was opened and confirms public participation.",
        "Change-index entries were reviewed, not individual version diffs. The brief welcomes newly disclosed issues case by case but normally excludes bounties within 14 days of a public patch.",
        "USD normalization uses platform accounting documentation; the brief itself uses dollar signs. No individual award or payment is established.",
        "Public policy pages only; authenticated submission and incorporated legal documents were not exhaustively reviewed. Asset inventories and testing instructions are omitted. Live terms prevail; this summary grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Vinted Bug Bounty public brief",
          "url": "https://bugcrowd.com/engagements/vinted-uab-mbb",
          "publisher": "Vinted / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "announcements",
          "title": "Vinted Bug Bounty announcements",
          "url": "https://bugcrowd.com/engagements/vinted-uab-mbb/announcements",
          "publisher": "Vinted / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "changelog",
          "title": "Vinted Bug Bounty change index",
          "url": "https://bugcrowd.com/engagements/vinted-uab-mbb/changelog",
          "publisher": "Vinted / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd Organization Accounting",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/vinted-uab-mbb/changelog/762b2474-e004-41d0-b720-c050b4e16705.json",
          "publisher": "Vinted",
          "retrieved_at": "2026-10-03T14:56:27Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:27Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "www.vinted.com",
            "asset_type": "website",
            "location": "https://www.vinted.com",
            "group": "Primary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.vinted.net",
            "asset_type": "website",
            "location": "https://www.vinted.net",
            "group": "Primary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.vintedgo.com",
            "asset_type": "website",
            "location": "https://www.vintedgo.com",
            "group": "Primary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Vinted iOS application",
            "asset_type": "ios",
            "location": "https://apps.apple.com/us/app/vinted-pre-loved-marketplace/id632064380",
            "group": "Primary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Vinted Android application",
            "asset_type": "android",
            "location": "https://play.google.com/store/apps/details?id=fr.vinted",
            "group": "Primary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Vinted Go Sandbox",
            "asset_type": "website",
            "location": "https://sandbox.vintedgo.com",
            "group": "Secondary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Vinted Sandbox",
            "asset_type": "website",
            "location": "https://sandbox.vinted.com",
            "group": "Secondary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Vinted Go Escalations test",
            "asset_type": "website",
            "location": "https://test-escalations.vintedgo.com",
            "group": "Secondary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Encryption Service",
            "asset_type": "website",
            "location": "https://badger.it.vinted.com",
            "group": "Secondary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Vinted Careers",
            "asset_type": "website",
            "location": "https://careers.vinted.com",
            "group": "Secondary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "Company Vinted",
            "asset_type": "website",
            "location": "https://company.vinted.com",
            "group": "Secondary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "News Vinted",
            "asset_type": "website",
            "location": "https://news.vinted.com",
            "group": "Secondary Target Group",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    },
    {
      "schema_version": "1.5.0",
      "id": "web-com-bug-bounty",
      "name": "Web.com Bug Bounty",
      "operator": "Newfold Digital / Web.com",
      "platform": "Bugcrowd",
      "program_type": {
        "value": "paid_bounty",
        "summary": "The reviewed official policy or reward guidelines advertise monetary bounties for eligible reports. This classification does not establish current submission acceptance or guarantee an individual award.",
        "source_ids": [
          "policy",
          "announcements"
        ]
      },
      "program_url": "https://bugcrowd.com/engagements/webdotcom",
      "policy_url": "https://bugcrowd.com/engagements/webdotcom",
      "announcement_urls": [
        "https://bugcrowd.com/engagements/webdotcom/announcements"
      ],
      "change_log_url": "https://bugcrowd.com/engagements/webdotcom/changelog",
      "rewards": {
        "currency": "USD",
        "minimum": 250,
        "maximum": 5000,
        "basis": "advertised_not_individual_award",
        "summary": "The current chart advertises a $5,000 maximum separately from bands of P1 $2,000–$3,000, P2 $1,000–$1,500 and P3 $250–$600. The opened February 22, 2024 notice confirms these reduced rates. Ratings remain discretionary; no actual award is asserted.",
        "source_ids": [
          "policy",
          "announcements",
          "currency"
        ]
      },
      "eligibility": {
        "summary": "Newfold Digital and subsidiary employees, their family members, current vendors and vendor employees are excluded; sanctions and export-control restrictions apply. Reports require reproducible security impact. Platform first-valid-report rules apply; monetary compensation requires age 18 or the applicable age of majority.",
        "source_ids": [
          "policy",
          "platform-terms"
        ]
      },
      "restrictions": {
        "summary": "Only explicitly covered services qualify. Real-customer interaction and disruption are prohibited; researcher identification is required and expenses are not reimbursed. Shared root causes receive one bounty. Intended own-page scripting, low-impact findings, third-party components and recently disclosed issues are excluded. Public disclosure is prohibited.",
        "source_ids": [
          "policy"
        ]
      },
      "submission_status": {
        "value": "accepting_reports",
        "summary": "The official brief explicitly displays In progress and an ongoing period, with a submission link. Individual eligibility remains subject to live terms.",
        "source_ids": [
          "policy"
        ]
      },
      "last_verified_at": "2026-10-03T01:52:33Z",
      "limitations": [
        "Brief and reviewed change index show September 11, 2026 as the latest revision. Only page 1 of 2 of the change index was reviewed; individual diffs were not opened.",
        "The announcement archive and February 22, 2024 reward notice were opened. The September 11, 2026 AI-builder notice was read within the brief; other archive bodies were not exhaustively reviewed.",
        "The chart does not explain when an award could exceed the ordinary P1 band to reach the separate $5,000 maximum.",
        "USD normalization uses platform accounting documentation; the brief itself uses dollar signs. No individual award or payment is established.",
        "Public policy pages only; authenticated submission and incorporated legal documents were not exhaustively reviewed. Asset inventories and testing instructions are omitted. Live terms prevail; this summary grants no authorization."
      ],
      "sources": [
        {
          "id": "policy",
          "title": "Web.com Bug Bounty public brief",
          "url": "https://bugcrowd.com/engagements/webdotcom",
          "publisher": "Newfold Digital / Web.com / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "announcements",
          "title": "Web.com Bug Bounty announcements",
          "url": "https://bugcrowd.com/engagements/webdotcom/announcements",
          "publisher": "Newfold Digital / Web.com / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "changelog",
          "title": "Web.com Bug Bounty change index",
          "url": "https://bugcrowd.com/engagements/webdotcom/changelog",
          "publisher": "Newfold Digital / Web.com / Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "browser"
        },
        {
          "id": "currency",
          "title": "Bugcrowd Organization Accounting",
          "url": "https://docs.bugcrowd.com/customers/fund-management/overview/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "platform-terms",
          "title": "Bugcrowd Standard Disclosure Terms",
          "url": "https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/",
          "publisher": "Bugcrowd",
          "retrieved_at": "2026-10-03T01:52:33Z",
          "provenance": "official_primary",
          "access_method": "text"
        },
        {
          "id": "assets-scope-2026-10-03",
          "title": "Published Bugcrowd scope groups",
          "url": "https://bugcrowd.com/engagements/webdotcom/changelog/cdf0a5a7-3e14-4bd2-8997-a9567e0bb63e.json",
          "publisher": "Newfold Digital / Web.com",
          "retrieved_at": "2026-10-03T14:56:28Z",
          "provenance": "official_primary",
          "access_method": "text"
        }
      ],
      "content_scope": "public_program_policy_summary",
      "rights": "Original summary CC BY 4.0; linked sources and trademarks retain their own rights.",
      "asset_scope": {
        "capture_status": "published_list",
        "collection_method": "official_platform_scope_table",
        "verified_at": "2026-10-03T14:56:28Z",
        "source_ids": [
          "assets-scope-2026-10-03"
        ],
        "in_scope": [
          {
            "name": "app.web.com",
            "asset_type": "website",
            "location": "https://app.web.com",
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "www.networksolutions.com",
            "asset_type": "website",
            "location": "https://www.networksolutions.com",
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://www.bluehost.com/",
            "asset_type": "website",
            "location": "https://www.bluehost.com/",
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://www.hostgator.com/",
            "asset_type": "website",
            "location": "https://www.hostgator.com/",
            "group": "In Scope ",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "out_of_scope": [
          {
            "name": "*.web.com",
            "asset_type": "website",
            "location": "https://*.web.com",
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.register.com",
            "asset_type": "website",
            "location": "https://*.register.com",
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.networksolutions.com",
            "asset_type": "website",
            "location": "https://*.networksolutions.com",
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "https://app.gator.com/",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.bluehost.com",
            "asset_type": "website",
            "location": null,
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          },
          {
            "name": "*.hostgator.com",
            "asset_type": "website",
            "location": "https://*.hostgator.com",
            "group": "Out of Scope Targets",
            "source_ids": [
              "assets-scope-2026-10-03"
            ]
          }
        ],
        "limitations": [
          "Published target group rows were captured; group descriptions, rules and exclusions may further narrow permitted research."
        ]
      }
    }
  ]
}
