[{"id":3623179,"new_policy":"Smule welcomes working with the security community to resolve security vulnerabilities in order to keep our customers safe! We will make a best effort to respond to incoming reports and keep you informed about our progress toward resolving any issues.\n\n# Vulnerability Disclosure\n* If you have identified a potential security vulnerability in our technology, please submit us a detailed report with reproducible steps.\n* Follow HackerOne's [disclosure guidelines](https://hackerone.com/disclosure-guidelines).\n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.\n\n# Scope\nAny production public-facing website owned \u0026 operated by Smule. Any application published on the Apple App Store or Google Play Store published by Smule.\n\n# Restrictions \u0026 Exclusions\n**The use of automated scanning against the web or API are strictly prohibited and will result in IP bans along with rejection of any findings**\n\nThe following issues fall outside the scope of our VDP:\n* No Social engineering attacks (e.g. phishing, vishing, smishing) \n* No physical attacks of Smule’s office or data centers are permitted\n* No Denial-of-Service attacks\n* Brute force attacks\n* No beta or other pre-production/testing environments\n* No 3rd party party hosted applications (ex: status pages, customer support systems)\n* Outdated TLS configurations which remain to support legacy Android\n* Clickjacking attacks without a documented series of clicks that produce a vulnerability\n* Email (including SPF/DKIM/DMARC)\n* Missing HTTP headers, unless a vulnerability can be demonstrated\n* Assumed vulnerabilities based upon version numbers only\n* Insecure cookie settings for non-sensitive cookies\n* Bugs requiring exceedingly unlikely user interaction\n* Smule reserves the right to make the final decision on the  classification of all vulnerability reports. We may mark reports as duplicate, non-applicable or otherwise, at our own discretion.\n\n# Rewards\n* We do not offer a bug bounty at this time, but certain vulnerabilities with a working proof of concept on some of our Android mobile app(s) may qualify for a bounty through the [Google Play Security Rewards Program](https://hackerone.com/googleplay). To see which apps and vulnerabilities may qualify for a bounty, please refer to the [Google Play Security Rewards Program’s Scope and Vulnerability Criteria](https://hackerone.com/googleplay).\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2019-11-07T23:55:57.253Z"},{"id":3600445,"new_policy":"Smule welcomes working with the security community to resolve security vulnerabilities in order to keep our customers safe. We will make a best effort to respond to incoming reports and keep you informed about our progress toward resolving any issues.\n\n# Vulnerability Disclosure\n* If you have identified a potential security vulnerability in our technology, please submit us a detailed report with reproducible steps.\n* Follow HackerOne's [disclosure guidelines](https://hackerone.com/disclosure-guidelines).\n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.\n\n# Scope\nAny production public-facing website owned \u0026 operated by Smule. Any application published on the Apple App Store or Google Play Store published by Smule.\n\n# Restrictions \u0026 Exclusions\n**The use of automated scanning against the web or API are strictly prohibited and will result in IP bans along with rejection of any findings**\n\nThe following issues fall outside the scope of our VDP:\n* No Social engineering attacks (e.g. phishing, vishing, smishing) \n* No physical attacks of Smule’s office or data centers are permitted\n* No Denial-of-Service attacks\n* Brute force attacks\n* No beta or other pre-production/testing environments\n* No 3rd party party hosted applications (ex: status pages, customer support systems)\n* Outdated TLS configurations which remain to support legacy Android\n* Clickjacking attacks without a documented series of clicks that produce a vulnerability\n* Email (including SPF/DKIM/DMARC)\n* Missing HTTP headers, unless a vulnerability can be demonstrated\n* Assumed vulnerabilities based upon version numbers only\n* Insecure cookie settings for non-sensitive cookies\n* Bugs requiring exceedingly unlikely user interaction\n* Smule reserves the right to make the final decision on the  classification of all vulnerability reports. We may mark reports as duplicate, non-applicable or otherwise, at our own discretion.\n\n# Rewards\n* We do not offer a bug bounty at this time, but certain vulnerabilities with a working proof of concept on some of our Android mobile app(s) may qualify for a bounty through the [Google Play Security Rewards Program](https://hackerone.com/googleplay). To see which apps and vulnerabilities may qualify for a bounty, please refer to the [Google Play Security Rewards Program’s Scope and Vulnerability Criteria](https://hackerone.com/googleplay).\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2019-01-14T15:58:22.510Z"},{"id":3593522,"new_policy":"Smule welcomes working with the security community to resolve security vulnerabilities in order to keep our customers safe. We will make a best effort to respond to incoming reports and keep you informed about our progress toward resolving any issues.\n\n# Vulnerability Disclosure\n* If you have identified a potential security vulnerability in our technology, please submit us a detailed report with reproducible steps.\n* Follow HackerOne's [disclosure guidelines](https://hackerone.com/disclosure-guidelines).\n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.\n\n# Scope\nAny production public-facing website owned \u0026 operated by Smule. Any application published on the Apple App Store or Google Play Store published by Smule.\n\n# Restrictions \u0026 Exclusions\n**The use of automated scanning against the web or API are strictly prohibited and will result in IP bans along with rejection of any findings**\n\nThe following issues fall outside the scope of our VDP:\n* No Social engineering attacks (e.g. phishing, vishing, smishing) \n* No physical attacks of Smule’s office or data centers are permitted\n* No Denial-of-Service attacks\n* No beta or other pre-production/testing environments\n* No 3rd party party hosted applications (ex: status pages, customer support systems)\n* Outdated TLS configurations which remain to support legacy Android\n* Clickjacking attacks without a documented series of clicks that produce a vulnerability\n* Email (including SPF/DKIM/DMARC)\n* Missing HTTP headers, unless a vulnerability can be demonstrated\n* Assumed vulnerabilities based upon version numbers only\n* Insecure cookie settings for non-sensitive cookies\n* Bugs requiring exceedingly unlikely user interaction\n* Smule reserves the right to make the final decision on the  classification of all vulnerability reports. We may mark reports as duplicate, non-applicable or otherwise, at our own discretion.\n\n# Rewards\n* We do not offer a bug bounty at this time, but certain vulnerabilities with a working proof of concept on some of our Android mobile app(s) may qualify for a bounty through the [Google Play Security Rewards Program](https://hackerone.com/googleplay). To see which apps and vulnerabilities may qualify for a bounty, please refer to the [Google Play Security Rewards Program’s Scope and Vulnerability Criteria](https://hackerone.com/googleplay).\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2018-11-03T16:02:39.594Z"},{"id":3593429,"new_policy":"Smule welcomes working with the security community to resolve security vulnerabilities in order to keep our customers safe. We will make a best effort to respond to incoming reports and keep you informed about our progress toward resolving any issues.\n\n# Vulnerability Disclosure\n* If you have identified a potential security vulnerability in our technology, please submit us a detailed report with reproducible steps.\n* Follow HackerOne's [disclosure guidelines](https://hackerone.com/disclosure-guidelines).\n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.\n\n# Scope\nAny production public-facing website owned \u0026 operated by Smule. Any application published on the Apple App Store or Google Play Store published by Smule.\n\n# Restrictions \u0026 Exclusions\nThe following issues fall outside the scope of our VDP:\n* No Social engineering attacks (e.g. phishing, vishing, smishing) \n* No physical attacks of Smule’s office or data centers are permitted\n* No high speed automated scanning\n* No Denial-of-Service attacks\n* No beta or other pre-production/testing environments\n* No 3rd party party hosted applications (ex: status pages, customer support systems)\n* Outdated TLS configurations which remain to support legacy Android\n* Clickjacking attacks without a documented series of clicks that produce a vulnerability\n* Email (including SPF/DKIM/DMARC)\n* Missing HTTP headers, unless a vulnerability can be demonstrated\n* Assumed vulnerabilities based upon version numbers only\n* Insecure cookie settings for non-sensitive cookies\n* Bugs requiring exceedingly unlikely user interaction\n* Smule reserves the right to make the final decision on the  classification of all vulnerability reports. We may mark reports as duplicate, non-applicable or otherwise, at our own discretion.\n\n# Rewards\n* We do not offer a bug bounty at this time, but certain vulnerabilities with a working proof of concept on some of our Android mobile app(s) may qualify for a bounty through the [Google Play Security Rewards Program](https://hackerone.com/googleplay). To see which apps and vulnerabilities may qualify for a bounty, please refer to the [Google Play Security Rewards Program’s Scope and Vulnerability Criteria](https://hackerone.com/googleplay).\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2018-11-02T17:59:48.442Z"},{"id":3593428,"new_policy":"Smule welcomes working with the security community to resolve security vulnerabilities in order to keep our customers safe. We will make a best effort to respond to incoming reports and keep you informed about our progress toward resolving any issues.\n\n# Vulnerability Disclosure\n* If you have identified a potential security vulnerability in our technology, please submit us a detailed report with reproducible steps.\n* Follow HackerOne's [disclosure guidelines](https://hackerone.com/disclosure-guidelines).\n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with explicit permission of the account holder.\n\n# Scope\nAny production public-facing website owned \u0026 operated by Smule. Any application published on the Apple App Store or Google Play Store published by Smule.\n\n# Restrictions \u0026 Exclusions\nThe following issues fall outside the scope of our VDP:\n* No Social engineering attacks (e.g. phishing, vishing, smishing) \n* No physical attacks of Smule’s office or data centers are permitted\n* No high speed automated scanning\n* No Denial-of-Service attacks\n* No beta or other pre-production/testing environments\n* No 3rd party party hosted applications (ex: status pages, customer support systems)\n* Outdated TLS configurations which remain to support legacy Android\n* Clickjacking attacks without a documented series of clicks that produce a vulnerability\n* Email (including SPF/DKIM/DMARC)\n* Missing HTTP headers, unless a vulnerability can be demonstrated\n* Assumed vulnerabilities based upon version numbers only\n* Insecure cookie settings for non-sensitive cookies\n* Bugs requiring exceedingly unlikely user interaction\n* Smule reserves the right to make the final decision on the  classification of all vulnerability reports. We may mark reports as duplicate, non-applicable or otherwise, at our own discretion.\n\n# Rewards\n* We do not offer a bug bounty at this time, but certain vulnerabilities with a working proof of concept on some of our Android mobile app(s) may qualify for a bounty through the [Google Play Security Rewards Program](https://hackerone.com/googleplay). To see which apps and vulnerabilities may qualify for a bounty, please refer to the [Google Play Security Rewards Program’s Scope and Vulnerability Criteria](https://hackerone.com/googleplay).\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2018-11-02T17:52:53.198Z"}]