vulns.co
/
GKData.io MCP

OneTrust · 2 min read

OneTrust Bug Bounty

OneTrust · Bugcrowd. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Use assigned or self-created accounts in the designated staging environment. Avoid shared-setting changes and disruption. Social engineering is prohibited. Public disclosure is prohibited; safe harbor is conditional.

Eligibility and submission status

Current employees, those employed within 12 months, customers and customer-engaged testing companies are excluded. Platform first-valid-report rules apply; monetary compensation requires age 18 or the applicable age of majority.

The official brief explicitly displays In progress and an ongoing period.

Advertised rewards

Advertised bands span USD 300–6,500; CVSS, likelihood and impact influence rewards. Downgrades allow appeal; duplicate causes do not receive multiple awards.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 1 published rows
AssetTypeGroup / eligibility
https://pentest-app.onetrust.com/websiteIn-Scope Targets
Out of scope · 26 published rows
AssetTypeGroup / eligibility
https://*.onetrust.comwebsiteOut-of-Scope Targets
https://store.onetrust.comwebsiteOut-of-Scope Targets
https://*.convercent.comwebsiteOut-of-Scope Targets
https://*.dataguidance.comwebsiteOut-of-Scope Targets
https://app.vendorpedia.comwebsiteOut-of-Scope Targets
https://*.preferencechoice.comwebsiteOut-of-Scope Targets
https://*.redacted.aiwebsiteOut-of-Scope Targets
https://*.sharedassessments.orgwebsiteOut-of-Scope Targets
https://developer.onetrust.comwebsiteOut-of-Scope Targets
https://my.onetrust.comwebsiteOut-of-Scope Targets
https://*.vendorpedia.comwebsiteOut-of-Scope Targets
https://*.onetrustgrc.comwebsiteOut-of-Scope Targets
https://*.cookiepro.comwebsiteOut-of-Scope Targets
https://tv.onetrust.com/websiteOut-of-Scope Targets
https://*.cookielaw.orgwebsiteOut-of-Scope Targets
https://*.onetrustpro.comwebsiteOut-of-Scope Targets
https://*.privacyconnect.comwebsiteOut-of-Scope Targets
https://*.onetrust.dewebsiteOut-of-Scope Targets
https://*.onetrust.sewebsiteOut-of-Scope Targets
https://*.onetrust.eswebsiteOut-of-Scope Targets
https://*.onetrust.frwebsiteOut-of-Scope Targets
https://*.onetrust.itwebsiteOut-of-Scope Targets
https://*.privacytech.comwebsiteOut-of-Scope Targets
https://*.privacypedia.comwebsiteOut-of-Scope Targets
https://*.esgiq.comwebsiteOut-of-Scope Targets
https://*.trustweek2021.comwebsiteOut-of-Scope Targets

Review limitations

  • Brief revision: December 22, 2025; newer announcements exist. Change index: page 1 of 2; diffs unreviewed.
  • April 21, 2026 exposure notice opened separately. No broader active-testing permission is inferred.
  • USD uses platform accounting evidence. Browser-only recovery; attachment, authenticated credential access and complete legal terms unreviewed. Inventories/instructions omitted; live terms prevail. No authorization granted.

Sources and provenance

  1. OneTrust Bug Bounty public brief OneTrust / Bugcrowd · reviewed 2026-10-03
  2. OneTrust Bug Bounty announcement archive OneTrust / Bugcrowd · reviewed 2026-10-03
  3. OneTrust Bug Bounty change index OneTrust / Bugcrowd · reviewed 2026-10-03
  4. Bugcrowd Organization Accounting Bugcrowd · reviewed 2026-10-03
  5. Bugcrowd Standard Disclosure Terms Bugcrowd · reviewed 2026-10-03
  6. Published Bugcrowd scope groups OneTrust · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software