[{"id":3761484,"new_policy":"# Disclosure Policy\n* Please do not discuss any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n# Program Rules\nPlease provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n* Submit one vulnerability per report unless you need to chain vulnerabilities to provide impact.\n* When duplicates occur, we only award the first report received (provided it can be fully reproduced).\n* Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n* Social engineering (e.g., phishing, vishing, smishing) is prohibited.\n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service.\n* Ask the program team **before submitting vulnerabilities on unscoped subdomains**\n* Only interact with accounts you own or with the explicit permission of the account holder.\n\n# Test Plan\n\n* Access the primary test environment using the provided test credentials. New researchers on the platform may not be able to claim credentials as per Hackerone guidelines and we will not be able to provide the same via email.  \n* Test environment : https://uat-bugbounty.nonprod.syfe.com/\n* Note: Findings on the test environment need to be reproducible on the production environment for the finding to be eligible.\n\n# Non-Qualifying Bugs/Known Issues\n\nTypically, the following types of bugs and activities are not eligible for a bounty :\n* Security vulnerabilities on sites hosted by third parties (e.g. help.syfe.com) unless they lead to a vulnerability on a Syfe main app\n* Denial of service (DoS) on Syfe infrastructure\n* Spamming\n* Social Engineering\n* Missing best practices in SSL/TLS configuration\n* Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n* Bugs affecting outdated or unpatched browsers\n* Rate-limit issues (unless reproducible on production)\n* Information disclosure on UAT environment\n* Previously known vulnerable libraries without a working Proof of Concept.\n* Open redirect - unless an additional security impact can be demonstrated\n* DOM XSS via redirect-url (widespread issue for which fix is already in progress)\n* Promo code URLs on web archive, Promo code enumeration.\n* Root detection/Jailbreak detection/SSL Pinning bypass\n* Credential leakage reports are considered informational if two-factor authentication (2FA) is in place\n* Rate limiting or brute force issues unless they can be abused for account takeover or financial damages\n* Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n* Self XSS/File Upload XSS\n* Edit own account details for non-KYC verified accounts.\n* Response manipulation that only affects the UI and no actual access to any accounts/features.\n* CORS related issues unless you can exfiltrate data.\n* Debug View/login into any account on UAT.\n* Exposed API keys without a proof of concept.\n* Pasting authorization token from another account to access their details. \n\n# Disqualifiers\n\n* Any modification or destruction of user data\n* Overwhelming our support team with messages.\n* Taking any steps that intentionally violate the privacy of our users\n* Denial of service, either against company infrastructure or user accounts\n* Social engineering of any kind against our users or employees\n* Any type of brute-forcing or automated attack techniques on production.\n\n\n# Session Layer: HTTP Headers\n\nFor production environments, researchers should add headers to requests such as:\n* “X-HackerOne-Research: [H1 username]”\n\n**If you signup on production, use only @wearehackerone.com email address to be eligible for bounty and avoid any blocks.**\n\nThank you for helping keep Syfe and our users safe!\n\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":true,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":"","platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2025-08-21T06:22:57.325Z"},{"id":3753565,"new_policy":"# Disclosure Policy\n* Please do not discuss any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n# Program Rules\nPlease provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n* Submit one vulnerability per report unless you need to chain vulnerabilities to provide impact.\n* When duplicates occur, we only award the first report received (provided it can be fully reproduced).\n* Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n* Social engineering (e.g., phishing, vishing, smishing) is prohibited.\n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service.\n* Ask the program team **before submitting vulnerabilities on unscoped subdomains**\n* Only interact with accounts you own or with the explicit permission of the account holder.\n\n# Test Plan\n\n* Access the primary test environment using the provided test credentials.\n* Test environment : https://uat-bugbounty.nonprod.syfe.com/\n* Note: Findings on the test environment need to be reproducible on the production environment for the finding to be eligible.\n\n# Non-Qualifying Bugs/Known Issues\n\nTypically, the following types of bugs and activities are not eligible for a bounty :\n* Security vulnerabilities on sites hosted by third parties (e.g. help.syfe.com) unless they lead to a vulnerability on a Syfe main app\n* Denial of service (DoS) on Syfe infrastructure\n* Spamming\n* Social Engineering\n* Missing best practices in SSL/TLS configuration\n* Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n* Bugs affecting outdated or unpatched browsers\n* Rate-limit issues (unless reproducible on production)\n* Information disclosure on UAT environment\n* Previously known vulnerable libraries without a working Proof of Concept.\n* Open redirect - unless an additional security impact can be demonstrated\n* DOM XSS via redirect-url (widespread issue for which fix is already in progress)\n* Promo code URLs on web archive, Promo code enumeration.\n* Root detection/Jailbreak detection/SSL Pinning bypass\n* Credential leakage reports are considered informational if two-factor authentication (2FA) is in place\n* Rate limiting or brute force issues unless they can be abused for account takeover or financial damages\n* Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n* Self XSS/File Upload XSS\n* Edit own account details for non-KYC verified accounts.\n* Response manipulation that only affects the UI and no actual access to any accounts/features.\n* CORS related issues unless you can exfiltrate data.\n* Debug View/login into any account on UAT.\n* Exposed API keys without a proof of concept.\n\n# Disqualifiers\n\n* Any modification or destruction of user data\n* Overwhelming our support team with messages.\n* Taking any steps that intentionally violate the privacy of our users\n* Denial of service, either against company infrastructure or user accounts\n* Social engineering of any kind against our users or employees\n* Any type of brute-forcing or automated attack techniques on production\n\n\n# Session Layer: HTTP Headers\n\nFor production environments, researchers should add headers to requests such as:\n* “X-HackerOne-Research: [H1 username]”\n\n**If you signup on production, use only @wearehackerone.com email address to be eligible for bounty and avoid any blocks.**\n\nThank you for helping keep Syfe and our users safe!\n\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":true,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":"","platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2025-04-11T11:08:22.314Z"},{"id":3752220,"new_policy":"# Disclosure Policy\n* Please do not discuss any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n# Program Rules\nPlease provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n* Submit one vulnerability per report unless you need to chain vulnerabilities to provide impact.\n* When duplicates occur, we only award the first report received (provided it can be fully reproduced).\n* Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n* Social engineering (e.g., phishing, vishing, smishing) is prohibited.\n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service.\n* Ask the program team **before submitting vulnerabilities on unscoped subdomains**\n* Only interact with accounts you own or with the explicit permission of the account holder.\n\n# Test Plan\n\n* Access the primary test environment using the provided test credentials.\n* Test environment : https://uat-bugbounty.nonprod.syfe.com/\n* Note: Findings on the test environment need to be reproducible on the production environment for the finding to be eligible.\n\n# Non-Qualifying Bugs\n\nTypically, the following types of bugs and activities are not eligible for a bounty :\n* Security vulnerabilities on sites hosted by third parties (e.g. help.syfe.com) unless they lead to a vulnerability on a Syfe main app\n* Denial of service (DoS) on Syfe infrastructure\n* Spamming\n* Social Engineering\n* Missing best practices in SSL/TLS configuration\n* Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n* Bugs affecting outdated or unpatched browsers\n* Rate-limit issues (unless reproducible on production)\n* Information disclosure on UAT environment\n* Previously known vulnerable libraries without a working Proof of Concept.\n* Open redirect - unless an additional security impact can be demonstrated\n\n# Disqualifiers\n\n* Any modification or destruction of user data\n* Overwhelming our support team with messages.\n* Taking any steps that intentionally violate the privacy of our users\n* Denial of service, either against company infrastructure or user accounts\n* Social engineering of any kind against our users or employees\n* Any type of brute-forcing or automated attack techniques on production\n\n\n# Session Layer: HTTP Headers\n\nFor production environments, researchers should add headers to requests such as:\n* “X-HackerOne-Research: [H1 username]”\n\n**If you signup on production, use only @wearehackerone.com email address to be eligible for bounty and avoid any blocks.**\n\nThank you for helping keep Syfe and our users safe!\n\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":true,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":"","platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2025-03-24T07:25:05.045Z"},{"id":3751979,"new_policy":"# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n# Program Rules\nPlease provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n* Submit one vulnerability per report unless you need to chain vulnerabilities to provide impact.\n* When duplicates occur, we only award the first report received (provided it can be fully reproduced).\n* Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n* Social engineering (e.g., phishing, vishing, smishing) is prohibited.\n* Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service.\n* Ask the program team **before submitting vulnerabilities on unscoped subdomains**\n* Only interact with accounts you own or with the explicit permission of the account holder.\n\n# Test Plan\n\n* Access the primary test environment using the provided test credentials.\n* Test environment : https://uat-bugbounty.nonprod.syfe.com/\n* Note: Findings on the test environment need to be reproducible on the production environment for the finding to be eligible.\n\n\n# Session Layer: HTTP Headers\n\nFor production environments, researchers should add headers to requests such as:\n* “X-HackerOne-Research: [H1 username]”\n\nThank you for helping keep Syfe and our users safe!\n\n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2025-03-19T07:11:14.705Z"}]