Smartsheet is a cloud-based work execution platform that empowers collaboration, drives better decision making, and accelerates innovation for over 78,000 brands in 190 countries, including more than 75% of the Fortune 500. Smartsheet complements existing enterprise investments by deeply integrating with applications from Microsoft, Google, Salesforce, Jira, Slack and many others.
We appreciate all security concerns brought forth and are constantly striving to keep on top of the latest threats. Being proactive rather than reactive to emerging security issues is a foundational belief at Smartsheet. Every day new security issues and attack vectors emerge. Smartsheet strives to keep abreast of the latest security developments by, in part, working with world-class security researchers and companies. We appreciate the community's efforts in creating a more secure world.
Smartsheet will make a best effort to meet the following response targets for hackers participating in our program:
We’ll try to keep you informed about our progress throughout the process.
Our bounty table provides general guidelines, and all final decisions are at
the discretion of Smartsheet.
Well written submissions and friendly hackers may be subject to additional rewards.
Priority | Critical Severity | Low Severity Targets
Critical | $1250 - $2500 | $600 - $1000
High | $750 - $1500 | $350 - $750
Medium | $200 - $850 | $150 - $500
Low | $100 - $250 | $50 - $200
Informational | $0 | $0
Only test using @wearehackerone.com accounts, unless
More detailed access instructions and documentation can be found in the Structured Scope section of this brief.
As a condition of participation in this program, you hereby grant Smartsheet, its affiliates, and customers a perpetual, irrevocable, worldwide, royalty- free, transferable, sub-licensable (through multiple tiers) and non-exclusive license to use, reproduce, adapt, modify, publish, distribute, publicly perform, create a derivative work form, make, use, sell, offer for sale and import the Submission, as well as any materials submitted to Smartsheet in connection therewith, for any purpose.
You must comply with all applicable laws in connection with your participation in this program. As well, this program is not an offer of employment, nor of a contractual relationship between Smartsheet and any other party. You are also responsible for any applicable taxes associated with any reward you receive.
Do not access customer or employee personal information, pre-release Smartsheet content, or Smartsheet confidential information. You may only exploit, investigate, or target security bugs against your own accounts and/or your own devices. Testing must not violate any law, or disrupt or compromise any data or access data that is not yours; intentional access of customer data other than your own is prohibited. In the event that you access data that is not your own, please stop testing and submit the vulnerability, even if the finding is incomplete.
We may modify the terms of this program or terminate this program at any time. We will not apply changes to this program retroactively.
Contact us if you want more information.