vulns.co
/
GKData.io MCP

40 records / Open collection

Reviewed program profiles.

Public policy summaries with eligibility, advertised rewards, restrictions, and dated scope captures.

40 matching records

1Password HackerOne

1Password Bug Bounty

Ordinary research is restricted to owned accounts. Privacy violations, destruction, disruption and unauthorized disclosure are prohibited; automation is limited. Local-root scenarios, accepted design limitations and…

Reviewed 2026-10-02Read

ADAC Group Intigriti

ADAC Vulnerability Disclosure Program

Disclosure requires written consent. Social engineering, physical intrusion, denial-of-service and brute force are prohibited. Activity must stop at payment-entry requirements; automation is constrained.

Reviewed 2026-10-03Read

Adobe Intigriti

Adobe Public Bug Bounty

Product-specific plans override general guidance and constrain environments/accounts. AI-assisted findings need human validation. Privacy violations, disruption, social engineering, unapproved customer environments and…

Reviewed 2026-10-03Read

Apple Independent

Apple Security Bounty

Preserve confidentiality until Apple’s update and advisory; do not harm others’ data or availability. Apple Pay, non-public systems, third-party services, social engineering and unvalidated reports are excluded.

Reviewed 2026-10-03Read

Circle Internet Contract Services, LLC HackerOne

Arc Bug Bounty

Mainnet testing is prohibited; permitted research is confined to designated test or local environments. Use owned or explicitly authorized accounts/wallets, avoid other users’ data and financial loss, and do not disrupt…

Reviewed 2026-10-03Read

Atlassian Bugcrowd

Atlassian Bug Bounty

No customer data, others’ repositories, credential validation, automated scanners, social engineering, physical attacks or post-exploitation pivoting. Cloud denial-of-service and low-impact categories are excluded.…

Reviewed 2026-10-02Read

curl project HackerOne

curl Vulnerability Disclosure

Preserve privacy, data integrity and availability; no disruption, spam or social engineering. Allow remediation before disclosure. Reports may become public after handling and sensitive-content review. Safe harbor is…

Reviewed 2026-10-03Read

Dashlane Intigriti

Dashlane Vulnerability Disclosure Program

Only owned/authorized accounts. Prohibited: disruption, high-volume automation, automated account creation, social engineering, user-data interference, physical attacks and public video hosting.

Reviewed 2026-10-03Read

Dropbox Intigriti

Dropbox Bug Bounty

Use owned test accounts; do not access other users’ private data. No disruption, social engineering, physical intrusion or brute force. Scanner-only reports, unlisted properties and planned-deprecation products are…

Reviewed 2026-10-03Read

Exoscale / Akenes SA Intigriti

Exoscale Bug Bounty

Protect customer privacy, integrity and availability. Social engineering and disruption are prohibited; automation and researcher identification are constrained. Disclosure requires written consent.

Reviewed 2026-10-03Read

Fastmail Pty Ltd Direct Vendor Program

Fastmail Bug Bounty

Protect data integrity, privacy and service availability. Disruption and social engineering are prohibited. Intended email behavior, unlikely-interaction findings, third-party services, username enumeration, obsolete…

Reviewed 2026-10-03Read

GitHub HackerOne Submission Channel

GitHub Bug Bounty

Protect others’ information; no social engineering, physical attacks, volumetric disruption, spam or excessive automation. Product-specific exclusions apply; coordinate disclosure until a fix is public.

Reviewed 2026-10-03Read

GitLab HackerOne

GitLab Bug Bounty

Privacy violations, disruption, unverified automated reports and third-party/customer installations are excluded. A shared mitigation generally receives one award; GitLab determines severity and payment.

Reviewed 2026-10-02Read

Grafana Labs Intigriti

Grafana Labs Vulnerability Disclosure Program

Disclosure requires written consent. Spam, social engineering and physical intrusion are prohibited. Generic rules exclude automated scanning/reporting, while human-validated AI assistance is permitted.

Reviewed 2026-10-03Read

HackerOne HackerOne

HackerOne Security Bounty

Do not access customer programs, environments or data, or unauthorized third-party infrastructure. Encountering sensitive information requires stopping and notifying the program.

Reviewed 2026-10-02Read

Newfold Digital / HostGator LATAM Bugcrowd

HostGator LATAM Bug Bounty

Owned/authorized accounts only; no real-customer interaction, multiple accounts, brute force, social engineering, disruption or data damage. Public disclosure is prohibited; safe harbor is conditional.

Reviewed 2026-10-03Read

Intel Intigriti

Intel Vulnerability Disclosure Program

Others’ data cannot be accessed or retained; accidental exposure requires stopping and reporting. Disclosure needs written consent. Safe harbor excludes third parties.

Reviewed 2026-10-03Read

Ivo AI Intigriti

Ivo AI Vulnerability Disclosure Program

Activity must cease upon unintended sensitive-data or cross-account access. Disclosure needs written consent; disruption, social engineering, physical intrusion and brute force are prohibited.

Reviewed 2026-10-03Read

LaunchDarkly Bugcrowd

LaunchDarkly Managed Bug Bounty Engagement

Scope includes selected application, API, SDK and supporting services. Unlisted properties, third-party integrations, support interfaces, non-SDK repositories, scan-only results, low-impact findings, denial-of-service…

Reviewed 2026-10-02Read

MathWorks Bugcrowd

MATLAB Online - Ongoing Bug Bounty Engagement

Intended execution of user-supplied code is not itself a security finding. Unlisted properties and third-party services are excluded. No staff contact through product features, service disruption or persistent public…

Reviewed 2026-10-03Read

Microsoft Corporation MSRC

Microsoft Edge Bounty Program

Preserve customer data and availability; stop on unauthorized access, report immediately and delete retained data. No social engineering, disruptive automation, unauthorized credential use or post-compromise activity.…

Reviewed 2026-10-03Read

Moovit Bugcrowd

Moovit Managed Bug Bounty Program

Scope is limited to selected mobile functionality; web applications and embedded web content are excluded. Automated scanners, bulk account creation, disruptive requests, social engineering and third-party application…

Reviewed 2026-10-03Read

Mozilla Bugzilla

Mozilla Client Bug Bounty

Protect privacy and availability, use controlled accounts, report accidental data exposure and delete retained data after notification. Allow reasonable remediation time; no extortion or personal exploitation. Safe…

Reviewed 2026-10-03Read

Mozilla HackerOne

Mozilla Web Bug Bounty

Low/medium reports generally receive no bounty. Respect privacy, availability and coordinated-disclosure requirements.

Reviewed 2026-10-02Read

Nubank Brasil Bugcrowd

Nubank Brasil Managed Bug Bounty Program

Use owned/authorized accounts, protect privacy and availability, and observe monetary limits. Social engineering and disruption are prohibited. Disclosure needs consent; safe harbor is conditional.

Reviewed 2026-10-03Read

NVIDIA Intigriti

NVIDIA Public Bug Bounty

Scope covers selected Container Toolkit and CUDA Toolkit components, emphasizing real privilege-boundary impact. Unreleased Container Toolkit builds, theoretical findings and defects lacking security impact are…

Reviewed 2026-10-02Read

NxtPort Intigriti

NxtPort Vulnerability Disclosure Program

User-data access/alteration, operational disruption, harmful automation, social engineering, physical intrusion and denial-of-service are prohibited. Accidental sensitive-data exposure requires stopping, reporting and…

Reviewed 2026-10-03Read

Okta Bugcrowd

Okta Bug Bounty

Selected identity, device and access-management products are covered. Okta Classic and Okta Personal are marked out of scope. No automated scanners, denial-of-service, customer-instance access, customer-data effects,…

Reviewed 2026-10-02Read

OneTrust Bugcrowd

OneTrust Bug Bounty

Use assigned or self-created accounts in the designated staging environment. Avoid shared-setting changes and disruption. Social engineering is prohibited. Public disclosure is prohibited; safe harbor is conditional.

Reviewed 2026-10-03Read

OpenAI Bugcrowd

OpenAI Security Bug Bounty

Use only owned or expressly authorized accounts/data; avoid disruption, destruction, social engineering and unrelated third parties. Model-only content issues and intended sandbox behavior generally do not qualify.…

Reviewed 2026-10-02Read

Proton AG Direct Vendor Program

Proton Bug Bounty

Only explicitly included services qualify. No third-party, physical, social-engineering or disruptive activity, malware, data alteration, exfiltration or persistence. Stop and notify Proton upon finding a vulnerability…

Reviewed 2026-10-03Read

Rapyd Bugcrowd

Rapyd Bug Bounty

Owned accounts only. Stop on nonpublic-data access and delete retained information. No form automation, social engineering, disruption or third-party evidence hosting. Public disclosure is prohibited.

Reviewed 2026-10-03Read

Telegram Direct Vendor Program

Telegram Bug Bounty

No unlawful activity, privacy harm, disruption, physical access, spam or social engineering. Premature public or third-party disclosure forfeits eligibility. Unsupported scanner output and compromised-device scenarios…

Reviewed 2026-10-03Read

Arm Intigriti

Trusted Firmware Bug Bounty

Reports need human-validated, realistic security impact. Social engineering, physical intrusion and DDoS are prohibited; disclosure requires written consent. Conditional protections cannot authorize third-party systems.

Reviewed 2026-10-03Read

Vercel HackerOne

Vercel Bug Bounty

Limit activity to owned or expressly authorized accounts and data. Open-source findings must be reproduced locally, with no active production testing. No social engineering, disruption, persistence or retention of…

Reviewed 2026-10-03Read

Vinted Bugcrowd

Vinted Bug Bounty

Only expressly listed properties qualify. Protect production stability and use owned accounts and transactions; interaction with real members is prohibited. No high-volume scanning, disruption, social engineering or…

Reviewed 2026-10-03Read

Newfold Digital / Web.com Bugcrowd

Web.com Bug Bounty

Only explicitly covered services qualify. Real-customer interaction and disruption are prohibited; researcher identification is required and expenses are not reimbursed. Shared root causes receive one bounty. Intended…

Reviewed 2026-10-03Read

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software