{"id":"9133cdd7-eb7e-448d-b2c7-32b3dfa64720","engagementId":"7e3255c9-7fb0-4725-86c7-4f27b3d16cce","data":{"brief":{"id":"0207358f-867a-40a2-a53e-e986139216f3","name":"Directly","tagline":"CX Automation","description":"\u003cp\u003eDirectly invites you to test their primary webapp and any other discoverable subdomains or attack surface that's part of *.sandbox.directly.com. Upon receipt of your report, we promise to review and address any security issues in a timely manner and to communicate with you during our investigation and upon resolution.\u003cbr\u003e\nPlease note that Directly is only looking for sandbox environment issues (nothing in production). If you go into production sites, your IP may get banned. \u003c/p\u003e\n\n\u003cp\u003eThanks again for making Directly a safer place for our customers and experts by disclosing security issues responsibly! Good luck and happy hunting! \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRewards/ratings:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor initial ratings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e for the prioritization/rating of findings. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":null,"targetsOverview":"\u003cul\u003e\n\u003cli\u003eAny domain/property of Directly not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/li\u003e\n\u003cli\u003e\n\u003ca href=\"http://directly.github.io/demosite/qa/rtm/sandbox.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttp://directly.github.io/demosite/qa/rtm/sandbox.html\u003c/a\u003e is available to researchers but is a 3rd party and should not be considered Directly Attack Surface, Do not do security research here only use it as a resource for testing in the sandbox. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget info:\u003c/h2\u003e\n\n\u003ch3\u003esandbox.directly.com:\u003c/h3\u003e\n\n\u003cp\u003eThis is the primary point of focus for testing - which mirrors the production version of our app, but also provides a safer place to test in. Given that this is available for testing - please DO NOT perform any testing against the production version of the app.\u003c/p\u003e\n\n\u003cp\u003eFundamentally, Directly is an app that crowd-sources customer service - wherein customers crowd-source questions to power users by offering bounties on answering questions. Researchers are encouraged to self-provision as they're able, and to and test whatever functionality one can access (excepting functionalities specifically listed as out-of-scope).\u003c/p\u003e\n\n\u003ch3\u003e*.sandbox.directly.com/:\u003c/h3\u003e\n\n\u003cp\u003eAs the scope infers, you're free to test any subdomain of *.sandbox.directly.com that you're able to find - \u003cem\u003eprovided it isn't listed as out of scope.\u003c/em\u003e Please be aware that it is especially important that researchers do not submit requests to salesforce via *.sandbox.directly.com/schedule-a-demo/ \u003c/p\u003e\n\n\u003ch2\u003eFocus Areas - endpoints\u003c/h2\u003e\n\n\u003cp\u003einsidr: sandbox.directly.com\u003cbr\u003e\neapps: eapps.sandbox.directly.com\u003cbr\u003e\ncai-auto-responder: cai.sandbox.directly.com\u003cbr\u003e\nmessaging-api: api.sandbox.directly.com\u003cbr\u003e\nstatic-assets: assets.sandbox.directly.com\u003cbr\u003e\nds_pr: triageapi.sandbox.directly.com\u003cbr\u003e\nclassification_based_directly_routing_engine: dre.sandbox.directly.com\u003cbr\u003e\nReport Connector: https://report-connector.sandbox.directly.com\u003cbr\u003e\nURL Shortener: https://url-shortener.sandbox.directly.com\u003cbr\u003e\nExpert Dashboard: https://expert-dashboard.sandbox.directly.com/\u003c/p\u003e\n\n\u003ch2\u003eAccess/Credentials:\u003c/h2\u003e\n\n\u003cp\u003eTo register on our test environment, please visit \u003ca href=\"https://area-51.sandbox.directly.com/apply\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://area-51.sandbox.directly.com/apply\u003c/a\u003e and click apply now. Feel free to fill out the registration information and application however you'd like. You'll need to fill out all mandatory fields, including a profile picture. Once you've created an account, then you can go to \u003ca href=\"https://app.sandbox.directly.com/login/auth\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://app.sandbox.directly.com/login/auth\u003c/a\u003e to authenticate with your new set of credentials. \u003c/p\u003e\n\n\u003cp\u003eTo access the main function of the site, which is asking questions of experts, you can visit this page: \u003ca href=\"https://directly.github.io/demosite/qa/rtm/sandbox.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://directly.github.io/demosite/qa/rtm/sandbox.html\u003c/a\u003e. Asking questions here populates the area-51 with your questions for further testing. \u003cstrong\u003eNote! It is imperative that you visit the ask a question page in a separate browser so the question is not asked by your current account. This way, you'll be able to communicate to an unauthenticated user.\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eGuidelines:\u003c/h2\u003e\n\n\u003cp\u003eSecurity of user data and communication is of the utmost importance to Directly. In pursuit of the best possible security, we welcome responsible disclosure of any vulnerability you find. Principles of responsible disclosure include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not extract data from our infrastructure (including customer data, source code, data backups, configuration files).\u003c/li\u003e\n\u003cli\u003eIf you obtain access to our system, report your finding immediately. Do not attempt to pivot to other servers or elevate access.\u003c/li\u003e\n\u003cli\u003eAvoid scanning techniques that are likely to cause degradation of service to customers (e.g. by overloading the site). This includes the spamming of contact forms, support emails, Wordpress hits, etc. \u003c/li\u003e\n\u003cli\u003eKeep details of vulnerabilities secret for at least 60 days such that Directly has had a reasonable amount of time to remediate the vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ewww.directly.com, \u003c/li\u003e\n\u003cli\u003e\n\u003cem\u003e.directly.com/schedule-a-demo/\u003c/em\u003e OR /product/* OR /careers/* OR /about/* OR /legal/* OR /trust/* (these are our WPEngine hosted marketing site)\u003c/li\u003e\n\u003cli\u003eresources.directly.com/* (this is a hubspot blog)\u003c/li\u003e\n\u003cli\u003eIt is especially important that researchers do not submit requests to salesforce via *.directly.com/schedule-a-demo/ \u003c/li\u003e\n\u003cli\u003eAny Wordpress related URLs (wp-content, wp-includes, etc.) \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through this program, or inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"12a5dfca-23a4-488d-8baa-53f11bfbb2c0","name":"█████████████████","targets":[{"id":"2da14399-00df-48ac-aeff-fdea2eab70e9","uri":null,"name":"████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a6aeab10-7928-4d88-ac5a-dd1ddf2d11af","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2da14399-00df-48ac-aeff-fdea2eab70e9"}],"recentChangeFlags":null},{"id":"7d58bc9b-ed64-4302-9585-76a964425597","uri":null,"name":"███████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"49b58b9b-1502-4a14-a163-37aecd75bd50","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"7d58bc9b-ed64-4302-9585-76a964425597"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"7d58bc9b-ed64-4302-9585-76a964425597"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7d58bc9b-ed64-4302-9585-76a964425597"}],"recentChangeFlags":null},{"id":"02629e0b-6c1d-433f-ad26-bb0a39d185f6","uri":null,"name":"████████████████████████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"79bd9369-71c7-4d48-ad44-e5d7483911ea","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"02629e0b-6c1d-433f-ad26-bb0a39d185f6"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"02629e0b-6c1d-433f-ad26-bb0a39d185f6"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"02629e0b-6c1d-433f-ad26-bb0a39d185f6"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"36672a0a-dde9-4938-a56c-055b65ab4551","p1MaxCents":300000,"p1MinCents":250000,"p2MaxCents":200000,"p2MinCents":150000,"p3MaxCents":75000,"p3MinCents":50000,"p4MaxCents":30000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":2500,"max":3000},"2":{"min":1500,"max":2000},"3":{"min":500,"max":750},"4":{"min":250,"max":300},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"c0512308-ec3c-4a32-90a6-51c0b22d3d53","name":"████████████","targets":[{"id":"6f853539-70e9-4749-a4d3-d5ca4cef60e4","uri":null,"name":"████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"fc889ce1-444d-46fd-bcbf-4264cbd28f9f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6f853539-70e9-4749-a4d3-d5ca4cef60e4"}],"recentChangeFlags":null},{"id":"ff0b2c36-d562-4694-924a-822dbd6eba95","uri":null,"name":"████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e0e83e6d-1f67-4e7d-bf98-d568938cde84","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ff0b2c36-d562-4694-924a-822dbd6eba95"}],"recentChangeFlags":null},{"id":"6b909f23-039b-4fe5-b993-21020f820283","uri":null,"name":"████████████████████████████████████████████████████████████████████████████████████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0756ec50-9d8e-423f-8400-e62dd3ed11d1","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6b909f23-039b-4fe5-b993-21020f820283"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"7e3255c9-7fb0-4725-86c7-4f27b3d16cce","code":"directly","state":"in_progress_paused","endsAt":null,"bountyId":"ce72f502-de7b-4c0b-a575-db4e751b95a9","startsAt":"2018-05-03T17:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/990a/d21c/4ae0fe65/e2cd6ece639388ac6dde4715f0abe0c2_directly-marketing-logo-square-03.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"Program paused","lastTransitionAt":"2026-04-24T20:25:32.643Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/directly","changelogs":"/engagements/directly/changelog","submissions":null,"announcements":"/engagements/directly/announcements","hallOfFame":"/engagements/directly/hall_of_fames","crowdstream":"/engagements/directly/crowdstream"},"announcementsCount":4,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=directly\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/directly/engagement_subscribers","engagementChangelogsUrl":"/engagements/directly/changelog","publishedAt":"2026-04-24T20:25:32.674Z","engagementChangelogUrl":"/engagements/directly/changelog/9133cdd7-eb7e-448d-b2c7-32b3dfa64720","createUserFeedbacksUrl":"/engagements/directly/feedbacks","engagementCrowdstreamUrl":"/engagements/directly/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}