The scope of the bug bounty is :
Function | Domain |
---|---|
Customer Dashboard | app.datadome.co |
Customer API | customer-api.datadome.co |
Java Script | js.datadome.co |
Captcha | *.captcha-delivery.co |
Server Site API used by modules | api.datadome.co |
Client Side API used by JS or SDK | api-js.datadome.co |
Corporate Site | datadome.co or www.datadome.co |
Server-Side modules (in customer infrastructure) | docs.datadome.co |
Authentication | auth.datadome.co |
You can find all the information you need about DataDome on https://docs.datadome.co/docs
readme.com third-party is out of scope
auth.datadome.co is managed by Auth0 Third-Party, only DataDome direct vulnerability will be rewarded
Keep in mind this is a production environment, no data alterations are allowed inside DataDome infrastructure or on DataDome customer Cloud infrastructure, and, therefore, you must not affect the availability of the platform.
Please adhere to the following rules while performing research on this program:
We are happy to thank everyone who submits valid reports which help us improve the security of DataDome, however only those that meet the following eligibility requirements may receive a monetary reward:
Our security team will review each committed finding and establish communication as soon as possible to reproduce and solve the reported vulnerability. Please allow 5 working days for our initial response. We ask you to make a good faith effort to avoid privacy violations, destruction of data and interruption or degradation of our service during your research.
Scope Type | Scope Name |
---|---|
api | https://customer-api.datadome.co |
api | https://api.datadome.co |
api | https://api-js.datadome.co |
web_application | https://app.datadome.co |
web_application | https://datadome.co |
web_application | https://*.captcha-delivery.com |
web_application | https://auth.datadome.co |
web_application | https://bot-tester.datadome.co/ |
Scope Type | Scope Name |
---|---|
undefined | All domains not listed In-Scope |
undefined | Third-party widgets on www.datadome.co and app.datadome.co |
Firebounty have crawled on 2021-09-30 the program DataDome Bug Bounty on the platform Yeswehack.
FireBounty © 2015-2024