Keeper Security is transforming the way businesses and individuals protect their passwords and sensitive digital assets to significantly reduce cyber theft. Keeper is SOC 2 Certified, ISO 27001 Certified and utilizes best-in-class encryption to safeguard its customers. Keeper Security is committed to the industry best practice of responsible disclosure of potential security issues.
This Vulnerability Disclosure Policy sets out expectations when working with good-faith hackers,
as well as what you can expect from us.
If security testing and reporting are done within the guidelines of this policy, we:
For the initial prioritization/rating of findings, this program will use the Bugcrowd
Vulnerability Rating Taxonomy.
However, it is important to note that in some cases a vulnerability priority will be modified due
to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed
explanation will be provided to the researcher - along with the opportunity to appeal, and make
a case for a higher priority.
Note: To unwrap and display Vault <> Server communication on the Web Vault, open the developer tools and type:
enableNetworkLog()
This will allow you to see the request/response to the server in JSON
On the Admin Console, the command to log additional request/response is:
api.shouldLog=true
If you need additional debug help, feel free to email us at security@keepersecurity.com.
Any domain/property of Keeper Security not listed in the targets section is out of scope. This
includes any/all subdomains not listed above.
This program follows Bugcrowd’s standard disclosure terms.
For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.
This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.
This bounty requires explicit permission to disclose the results of a submission.
Scope Type | Scope Name |
---|---|
android_application | KeeperChat for Android |
android_application | Keeper for Android |
api | Keeper Secrets Manager |
api | Keeper SSO Connect On-Prem |
api | SSO Connect Cloud |
api | Keeper AD / LDAP Bridge |
ios_application | KeeperChat for iOS |
ios_application | Keeper for iOS |
undefined | KeeperChat for Windows |
undefined | KeeperChat for Mac |
undefined | Keeper for Mac, PC, Linux |
undefined | Keeper Admin Console (US) |
undefined | Keeper Admin Console (EU) |
undefined | Keeper Browser Extension |
web_application | Keeper Security Website |
web_application | Keeper Web Vault (US) |
web_application | Keeper Web Vault (EU) |
web_application | Keeper Web Vault (AU) |
This program feature scope type like undefined, android_application, api, ios_application, web_application.
FireBounty © 2015-2024