Policy and restrictions
Use assigned or self-created accounts in the designated staging environment. Avoid shared-setting changes and disruption. Social engineering is prohibited. Public disclosure is prohibited; safe harbor is conditional.
Eligibility and submission status
Current employees, those employed within 12 months, customers and customer-engaged testing companies are excluded. Platform first-valid-report rules apply; monetary compensation requires age 18 or the applicable age of majority.
The official brief explicitly displays In progress and an ongoing period.
Advertised rewards
Advertised bands span USD 300–6,500; CVSS, likelihood and impact influence rewards. Downgrades allow appeal; duplicate causes do not receive multiple awards.
Advertised schedules and exceptional ceilings are not individual award evidence.
Published scope snapshot
Captured 2026-10-03. Check the current policy for changes before participating.
| Asset | Type | Group / eligibility |
|---|---|---|
https://pentest-app.onetrust.com/ | website | In-Scope Targets |
| Asset | Type | Group / eligibility |
|---|---|---|
https://*.onetrust.com | website | Out-of-Scope Targets |
https://store.onetrust.com | website | Out-of-Scope Targets |
https://*.convercent.com | website | Out-of-Scope Targets |
https://*.dataguidance.com | website | Out-of-Scope Targets |
https://app.vendorpedia.com | website | Out-of-Scope Targets |
https://*.preferencechoice.com | website | Out-of-Scope Targets |
https://*.redacted.ai | website | Out-of-Scope Targets |
https://*.sharedassessments.org | website | Out-of-Scope Targets |
https://developer.onetrust.com | website | Out-of-Scope Targets |
https://my.onetrust.com | website | Out-of-Scope Targets |
https://*.vendorpedia.com | website | Out-of-Scope Targets |
https://*.onetrustgrc.com | website | Out-of-Scope Targets |
https://*.cookiepro.com | website | Out-of-Scope Targets |
https://tv.onetrust.com/ | website | Out-of-Scope Targets |
https://*.cookielaw.org | website | Out-of-Scope Targets |
https://*.onetrustpro.com | website | Out-of-Scope Targets |
https://*.privacyconnect.com | website | Out-of-Scope Targets |
https://*.onetrust.de | website | Out-of-Scope Targets |
https://*.onetrust.se | website | Out-of-Scope Targets |
https://*.onetrust.es | website | Out-of-Scope Targets |
https://*.onetrust.fr | website | Out-of-Scope Targets |
https://*.onetrust.it | website | Out-of-Scope Targets |
https://*.privacytech.com | website | Out-of-Scope Targets |
https://*.privacypedia.com | website | Out-of-Scope Targets |
https://*.esgiq.com | website | Out-of-Scope Targets |
https://*.trustweek2021.com | website | Out-of-Scope Targets |
Review limitations
- Brief revision: December 22, 2025; newer announcements exist. Change index: page 1 of 2; diffs unreviewed.
- April 21, 2026 exposure notice opened separately. No broader active-testing permission is inferred.
- USD uses platform accounting evidence. Browser-only recovery; attachment, authenticated credential access and complete legal terms unreviewed. Inventories/instructions omitted; live terms prevail. No authorization granted.
Sources and provenance
- OneTrust Bug Bounty public brief OneTrust / Bugcrowd · reviewed 2026-10-03
- OneTrust Bug Bounty announcement archive OneTrust / Bugcrowd · reviewed 2026-10-03
- OneTrust Bug Bounty change index OneTrust / Bugcrowd · reviewed 2026-10-03
- Bugcrowd Organization Accounting Bugcrowd · reviewed 2026-10-03
- Bugcrowd Standard Disclosure Terms Bugcrowd · reviewed 2026-10-03
- Published Bugcrowd scope groups OneTrust · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.