vulns.co
/
GKData.io MCP

HackerOne · 2 min read

Cloud Software Group

Paid Bounty

Open current program Scope capture

What this record establishes

Scope capture

Published asset rows were captured. The full policy and eligibility were not individually reviewed.

Directory row 320; Active program checkbox checked; Bounties minimum displayed $50. Positive displayed minimum supports paid bounty listing. Policy and live submission availability unverified.

Published asset scope

Snapshot captured 2026-10-03. Scope status: Captured.

In scope · 17 published rows
AssetTypeGroup / eligibility
ap-s.cloud.comURLBounty eligible: Yes
eu.cloud.comURLBounty eligible: Yes
us.cloud.comURLBounty eligible: Yes
*.citrixworkspacesapi.netURLBounty eligible: Yes
onboarding.cloud.comURLBounty eligible: Yes
onboarding-*.cloud.comURLBounty eligible: Yes
accounts.cloud.comURLBounty eligible: Yes
adm.cloud.comURLBounty eligible: Yes
api.adm.cloud.comURLBounty eligible: Yes
Citrix Secure Access client for WindowsOTHERBounty eligible: Yes
Citrix Secure Access client for iOSOTHERBounty eligible: Yes
Citrix Secure Access client for LinuxOTHERBounty eligible: Yes
Citrix End Point Analysis (EPA) client for LinuxOTHERBounty eligible: Yes
Citrix End Point Analysis (EPA) client for WindowsOTHERBounty eligible: Yes
Citrix Secure Access client for AndroidGOOGLE_PLAY_APP_IDBounty eligible: Yes
Citrix Secure Access client for macOSAPPLE_STORE_APP_IDBounty eligible: Yes
*developer.cloud.comURLBounty eligible: No
Out of scope · 16 published rows
AssetTypeGroup / eligibility
citrix.cloud.comURLBounty eligible: No
www.cloud.comURLBounty eligible: No
accounts-internal.cloud.comURLBounty eligible: No
launch.cloud.comURLBounty eligible: No
*.citrix*.comURLBounty eligible: No
*.cloudburrito.comURLBounty eligible: No
*.securevdr.comURLBounty eligible: No
*.podio.comURLBounty eligible: No
(yoursubdomain).us.iws.cloud.comURLBounty eligible: No
(yoursubdomain).ap.iws.cloud.comURLBounty eligible: No
(yoursubdomain).eu.iws.cloud.comURLBounty eligible: No
(youriwssubdomain).cloud.comURLBounty eligible: No
*.xmtest.cloud.comURLBounty eligible: No
*.xmqa.cloud.comURLBounty eligible: No
*.xmdev.cloud.comURLBounty eligible: No
*.browser.cloud.comOTHERBounty eligible: No

Capture limits

  • Only the published asset table was captured; program rules and eligibility still require individual review.

Live policy and platform eligibility still require review.

Sources and collection identity

  1. Official program page Primary source · reviewed 2026-10-03
  2. Published scope source Primary source · reviewed 2026-10-03

Appears in Discovery, Bounty. No identity match is inferred from a shared company name.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software