Since 2004, Indeed has given job seekers free access to millions of jobs from thousands of company websites and job boards. As the leading pay-for-performance recruitment advertising network, Indeed drives millions of targeted applicants to jobs in every field and is the most cost-effective source of candidates for thousands of companies. We take our security very seriously and welcome any responsible disclosure of potential gaps in our systems. Please read through the following details to help you focus on the areas most important to us.
If during your research you happen to encounter any information about another user or other individual, immediately stop and report this to Indeed. To participate in this program, you only need to explain the technical vulnerability you discovered.
Do not copy, save, store, transfer, disclose, or otherwise retain any information you find on our Site during your research, except to report your research to Indeed.
All access to our Site must otherwise be in accordance with our Terms of Service and all applicable laws.
In the event you access PII or other sensitive data, note that you are required to follow all laws and regulations applicable to the access and processing of such personally identifiable information and/or data, such as the California Consumer Privacy Act of 2018, the California Privacy Rights Act of 2020 once it becomes effective, and the European Union’s General Data Protection Regulation (Regulation (EU) 2016/679), including the European Commission’s Standard Contractual Clauses regarding the transfer of personal data to processors.
Research should be performed only through the job seeker, advertiser, and/or publisher account that you create on Indeed. Indeed regularly purges accounts that perform suspicious activities on our web properties; to avoid this, please use accounts with “+bugbounty” in the username for example: username+bugbounty@bugcrowdninja.com.
You must avoid any viewing, copying, altering, destroying, or otherwise interacting with any data, in particular data of other individuals, to which you may gain access through this research. If you happen to interact in any way with another individual's data, you must report this to us immediately.
If a vulnerability provides unintended access to data, limit the amount of data you access to the minimum required for effectively demonstrating the vulnerability, cease testing, and submit a report immediately if you encounter any user data during testing. This may include Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information.
You must avoid causing any interruption or degradation of our services. Researchers who are found to be using aggressive automated tools will be blocked and removed from the program.
Any form of interaction with others on or through our Site, including but not limited to other Indeed users, is strictly prohibited.
You will be expected to cooperate with us if we request your assistance in connection with your research.
This program follows Bugcrowd’s standard disclosure terms.
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
Scope Type | Scope Name |
---|---|
android_application | https://play.google.com/store/apps/developer?id=Indeed+Jobs |
api | https://reporting-plugin.indeed.com |
api | https://campaign-management-plugin.indeed.com |
api | https://analyticsperf-analytics.indeed.com |
ios_application | https://apps.apple.com/us/app/indeed-job-search/id309735670 |
web_application | .indeed.com/ |
web_application | https://analytics.indeed.com |
web_application | https://employers.indeed.com/ |
web_application | https://my.indeed.com |
web_application | https://billing.indeed.com |
web_application | https://resumes.indeed.com |
web_application | https://secure.indeed.com |
web_application | https://itaportal.indeed.com |
web_application | https://accounts.indeed.com |
web_application | https://central.indeed.com |
web_application | https://events.indeed.com |
web_application | https://evaluate.indeed.com |
web_application | https://www.indeed.com |
The progam has been crawled by Firebounty on 2015-06-30 and updated on 2020-02-18, 1378 reports have been received so far.
FireBounty © 2015-2024