vulns.co
/
GKData.io MCP

Dashlane · 2 min read

Dashlane Vulnerability Disclosure Program

Dashlane · Intigriti. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Only owned/authorized accounts. Prohibited: disruption, high-volume automation, automated account creation, social engineering, user-data interference, physical attacks and public video hosting.

Eligibility and submission status

Intigriti accounts and researcher identification are required. Reports need clear evidence, individual findings and exclusive coordinated submission. Platform adulthood/guardian-approved age-16 and legal/employer conditions apply.

Visible policies and login invitations do not verify acceptance.

Advertised rewards

Currency/bounds are inapplicable. Generic reward wording and possible private-program invitations do not promise cash.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 6 published rows
AssetTypeGroup / eligibility
*.dashlane.comWildcardTier 2
Dashlane Mobile ApplicationsOtherTier 2
Autofill and Autologin FunctionalityOtherTier 2
Dashlane Browser ExtensionsOtherTier 2
Dashlane Business and Enterprise FeaturesOtherTier 2
Out of ScopeOtherTier 2
Out of scope · 0 published rows
AssetTypeGroup / eligibility
No rows captured. This does not establish that the program has no assets or restrictions.

Review limitations

  • FAQ accepts reports on other Dashlane-controlled assets; broader reporting does not expand listed-only testing authorization.
  • No dedicated announcement/change-log or expanded safe-harbor text verified.
  • Logged-out review; authenticated eligibility and open/paused status unverified.
  • High-level context omits asset inventories and testing instructions. Live terms prevail; this record grants no authorization.
  • Historical average $185/total $925 payouts neither establish a current schedule nor an individual award; explicit no-bounty terms prevail.

Sources and provenance

  1. Dashlane Vulnerability Disclosure Program policy Dashlane / Intigriti · reviewed 2026-10-03
  2. Intigriti Researcher Terms & Conditions Intigriti · reviewed 2026-10-03
  3. Published Intigriti asset table Dashlane · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software