{"id":"0c2e8a25-07ad-4b8d-8846-a8a763faad93","engagementId":"0931c43d-9978-457e-881a-81460e5310a8","data":{"brief":{"id":"bcddfaf7-25c0-49b6-8627-ce1cf13446bd","name":"Keeper Security Public Bounty Program","tagline":"Keeper is the leading password management, privilege access management and secure messaging platform for consumers and businesses.","description":"\u003cp\u003eKeeper Security is transforming the way businesses and individuals protect their passwords and sensitive digital assets to significantly reduce cyber theft. Keeper is SOC 2 Certified, ISO 27001 Certified, FedRAMP Authorized and utilizes best-in-class encryption to safeguard its customers. Keeper Security is committed to the industry best practice of responsible disclosure of potential security issues. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eGuidelines:\u003c/h2\u003e\n\n\u003cp\u003eThis Vulnerability Disclosure Policy sets out expectations when working with good-faith hackers,\u003cbr\u003e\nas well as what you can expect from us.\u003c/p\u003e\n\n\u003cp\u003eIf security testing and reporting are done within the guidelines of this policy, we:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eConsider it to be authorized in accordance with Computer Fraud and Abuse Act,\u003c/li\u003e\n\u003cli\u003eConsider it exempt from DMCA, and will not bring a claim against you for bypassing any\nsecurity or technology controls,\u003c/li\u003e\n\u003cli\u003eConsider it legal, and will not pursue or support any legal action related to this program\nagainst you,\u003c/li\u003e\n\u003cli\u003eWill work with you to understand and resolve the issue quickly, and\u003c/li\u003e\n\u003cli\u003eWill recognize your contributions publicly if you are the first to report the issue and we make a\ncode or configuration change based on the issue.\n\u003cstrong\u003e\u003cem\u003eIf at any time you are concerned or uncertain about testing in a way that is consistent with the Guidelines and Scope of this policy, please contact us before proceeding.\u003c/em\u003e\u003c/strong\u003e\nTo encourage good-faith security testing and disclosure of discovered vulnerabilities, we ask that you:\u003c/li\u003e\n\u003cli\u003eAvoid violating privacy, harming user experience, disrupting production or corporate systems, and/or destroying data,\u003c/li\u003e\n\u003cli\u003ePerform research only within the scope set out below, and respect systems and activities\nwhich are out-of-scope,\u003c/li\u003e\n\u003cli\u003eContact us immediately if you encounter any user data during testing,\u003c/li\u003e\n\u003cli\u003eUse the identified communication channels to report vulnerability information to us and,\u003c/li\u003e\n\u003cli\u003eKeep information about any vulnerabilities you’ve discovered confidential until we’ve resolved\nthem.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd\u003cbr\u003e\nVulnerability Rating Taxonomy\u003c/a\u003e.\u003cbr\u003e\nHowever, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e\n\n\u003cp\u003ePlease review the Quality Reporting section for additional guidelines as it pertains to Ratings/Rewards\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eNote: To unwrap and display Vault \u0026lt;\u0026gt; Server communication on the Web Vault, open the developer tools and type:\u003cbr\u003e\nenableNetworkLog(true)\u003c/p\u003e\n\n\u003cp\u003eThis will allow you to see the request/response to the server in JSON\u003c/p\u003e\n\n\u003cp\u003eOn the Admin Console, the command to log additional request/response is:\u003cbr\u003e\napi.shouldLog=true\u003c/p\u003e\n\n\u003cp\u003eIf you need additional debug help, feel free to email us at security@keepersecurity.com.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eVRT Changes:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny submissions stemming from throttling or spam testing will be rated as a P4.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eAny domain/property of Keeper Security not listed in the targets section is out of scope. This\u003cbr\u003e\nincludes any/all subdomains not listed above.  This includes kepr.co and kepr.io.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003e\u003cem\u003eAny domain/property of Keeper Security not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess/Credentials\u003c/h2\u003e\n\n\u003cp\u003ePlease sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://researcherdocs.bugcrowd.com/v2.0/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eTarget Info\u003c/h2\u003e\n\n\u003ch1\u003eEnterprise License\u003c/h1\u003e\n\n\u003cp\u003eTo create a 14-day Enterprise trial license, follow \u003ca href=\"https://docs.keeper.io/enterprise-guide/start-free-trial\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ethis step by step guide\u003c/a\u003e. Once you're logged into the admin console, follow the instructions in the \u003ca href=\"https://docs.keeper.io/enterprise-guide/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAdmin Guide\u003c/a\u003e to set up other components such as SSO Connect Cloud, SSO Connect On-Prem, Active Directory Bridge, etc...\u003c/p\u003e\n\n\u003ch1\u003ePersonal License\u003c/h1\u003e\n\n\u003cp\u003eTo create a 30-day personal trial, go to the Web Vault in the destination region and click Create Account:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://keepersecurity.com/vault\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eWeb Vault (US)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://keepersecurity.eu/vault\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eWeb Vault (EU)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://keepersecurity.com.au/vault\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eWeb Vault (AU)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://keepersecurity.jp/vault\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eWeb Vault (JP)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://keepersecurity.ca/vault\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eWeb Vault (CA)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://govcloud.keepersecurity.us/vault\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eWeb Vault (US GovCloud)\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eQuality Reporting\u003c/h2\u003e\n\n\u003cp\u003eWhen reporting an issue to this program, please be sure to include the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIssue Name/Title of Vulnerability\u003c/li\u003e\n\u003cli\u003eDescription of the vulnerability identified\u003c/li\u003e\n\u003cli\u003eDescription of the impact\u003c/li\u003e\n\u003cli\u003eDetailed replication steps along with screenshots, in a step-by-step manner that could be followed by non-security personnel\u003c/li\u003e\n\u003cli\u003eImpacted/Affected URL/Domain\u003c/li\u003e\n\u003cli\u003eRisk rating of the identified vulnerability\u003c/li\u003e\n\u003cli\u003eCVSS score and business impact of the vulnerability to justify the risk rating\u003c/li\u003e\n\u003cli\u003eA real-world exploit scenario explaining what an attacker could do with this vulnerability and how they would do it\u003c/li\u003e\n\u003cli\u003eClear explanation of the required attacker position, prerequisites, and assumptions\u003c/li\u003e\n\u003cli\u003eEvidence that the issue creates meaningful security impact against another user, customer, tenant, or Keeper-managed system\u003c/li\u003e\n\u003cli\u003eActionable remediation guidance\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eSubmissions lacking detailed exploitation steps, validated impact, and a realistic exploit scenario will not be eligible for reward.\u003c/p\u003e\n\n\u003cp\u003eReports that are theoretical, speculative, based only on automated scanner output, or dependent on unrealistic assumptions are not eligible for reward.\u003c/p\u003e\n\n\u003ch1\u003eTargets\u003c/h1\u003e\n\n\u003cp\u003e\u003cem\u003eKeeperFill Browser Extension\u003c/em\u003e - \u003ca href=\"https://www.keepersecurity.com/download.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper Web Vault\u003c/em\u003e - \u003ca href=\"https://keepersecurity.com/vault\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper Admin Console\u003c/em\u003e - \u003ca href=\"https://keepersecurity.com/console\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper Desktop Application\u003c/em\u003e - \u003ca href=\"https://www.keepersecurity.com/download.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper Secrets Manager\u003c/em\u003e - \u003ca href=\"https://docs.keeper.io/secrets-manager/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper Commander\u003c/em\u003e - \u003ca href=\"https://docs.keeper.io/en/v/secrets-manager/commander-cli/overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper Connection Manager\u003c/em\u003e - \u003ca href=\"https://docs.keeper.io/keeper-connection-manager/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper SSO Connect Cloud\u003c/em\u003e - \u003ca href=\"https://docs.keeper.io/sso-connect-cloud/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper SSO Connect On-Prem\u003c/em\u003e - \u003ca href=\"https://docs.keeper.io/sso-connect-guide/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper AD Bridge\u003c/em\u003e - \u003ca href=\"https://docs.keeper.io/keeper-bridge/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper for iOS\u003c/em\u003e - \u003ca href=\"https://apps.apple.com/us/app/keeper-password-manager/id287170072\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper for Android\u003c/em\u003e - \u003ca href=\"https://play.google.com/store/apps/details?id=com.callpod.android_apps.keeper\u0026amp;hl=en_US\u0026amp;gl=US\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeperChat for iOS\u003c/em\u003e - \u003ca href=\"https://apps.apple.com/app/id1216446440\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeperChat for Android\u003c/em\u003e - \u003ca href=\"https://play.google.com/store/apps/details?id=com.keepersecurity.chat\u0026amp;hl=en_US\u0026amp;gl=US\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeperChat for Mac\u003c/em\u003e - \u003ca href=\"https://apps.apple.com/us/app/keeperchat/id1273303729?mt=12\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeperChat for Windows\u003c/em\u003e - \u003ca href=\"https://www.microsoft.com/en-us/p/keeperchat/9pdqtcpn4kxn\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper Website\u003c/em\u003e - \u003ca href=\"https://www.keepersecurity.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eKeeper Checkout Pages\u003c/em\u003e - \u003ca href=\"https://www.keepersecurity.com/checkout/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eClick Here\u003c/a\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAdditional Notes\u003c/h2\u003e\n\n\u003cp\u003ePlease keep in mind as you test the targets, particularly the websites, that these are production systems. Please abstain from running automated tools against contact forms or other areas where it appears the form may submit to a human or team on the other end.\u003c/p\u003e\n\n\u003cp\u003eManual testing is highly encouraged and recommended in such places and situations.\u003c/p\u003e\n\n\u003cp\u003eKeeper's server communication uses an AES transmission key on top of TLS, which makes it very difficult to intercept using typical tooling. On the Web Vault, to unwrap and display Vault \u0026lt;\u0026gt; Server communication, open the developer tools and type:\u003c/p\u003e\n\n\u003cp\u003eenableNetworkLog()\u003c/p\u003e\n\n\u003cp\u003eThis will allow you to see the request/response to the server in the output logs.\u003c/p\u003e\n\n\u003cp\u003eOn the Admin Console, the command to log additional request/response is:\u003c/p\u003e\n\n\u003cp\u003eenableLogging()\u003c/p\u003e\n\n\u003cp\u003eAlso note that Keeper device approval can be configured to use IP-based approval. To turn this on or off, visit the Vault settings screen of the vault. We are happy to assist you with debugging and product usage.\u003c/p\u003e\n\n\u003cp\u003eWe will disqualify any submission that is clearly AI slop. Any researcher that repeatedly sends AI-generated reports with no real-world impact may be disqualified.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProgram Focus\u003c/h2\u003e\n\n\u003cp\u003eThis program is focused on high-impact security vulnerabilities with a clear, realistic exploit path and material impact to Keeper, Keeper customers, or Keeper-managed data.\u003c/p\u003e\n\n\u003cp\u003eAccepted submissions should generally demonstrate impact consistent with P1 or P2 severity. Reports should show a practical attack path that results in one or more of the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthentication bypass\u003c/li\u003e\n\u003cli\u003eDevice approval bypass\u003c/li\u003e\n\u003cli\u003eRemote code execution\u003c/li\u003e\n\u003cli\u003eUnauthorized access to sensitive customer data, vault data, secrets, or administrative functionality\u003c/li\u003e\n\u003cli\u003eCross-tenant, cross-account, or cross-region data access\u003c/li\u003e\n\u003cli\u003eMeaningful privilege escalation\u003c/li\u003e\n\u003cli\u003eBypass of access controls or security controls protecting customer data\u003c/li\u003e\n\u003cli\u003eCryptographic, key-management, or encryption flaws with demonstrated exploitability and material impact\u003c/li\u003e\n\u003cli\u003eHigh-impact vulnerabilities in customer-facing web applications, APIs, desktop applications, mobile applications, or supported Keeper services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eReports must demonstrate realistic impact against another user, customer, tenant, or Keeper-managed system. Reports that affect only the researcher’s own account, require unrealistic assumptions, or do not demonstrate material security impact are not eligible for reward.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eThe following categories are in scope when the report demonstrates realistic P1/P2-level impact:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthentication bypass\u003c/li\u003e\n\u003cli\u003eDevice approval bypass\u003c/li\u003e\n\u003cli\u003eAuthorization bypass or access control failures\u003c/li\u003e\n\u003cli\u003eRemote code execution\u003c/li\u003e\n\u003cli\u003eMeaningful privilege escalation\u003c/li\u003e\n\u003cli\u003eUnauthorized access to sensitive customer data\u003c/li\u003e\n\u003cli\u003eCross-tenant or cross-account data exposure\u003c/li\u003e\n\u003cli\u003eHigh-impact information disclosure involving secrets, vault data, credentials, tokens, private keys, or administrative data\u003c/li\u003e\n\u003cli\u003eVulnerabilities in supported customer-facing web applications and APIs\u003c/li\u003e\n\u003cli\u003eVulnerabilities in supported desktop applications or mobile applications\u003c/li\u003e\n\u003cli\u003eCryptographic or key-management vulnerabilities with a demonstrated exploit path and material customer impact\u003c/li\u003e\n\u003cli\u003eCross-site scripting or cross-site request forgery only where the report demonstrates meaningful account, tenant, administrative, or sensitive-data impact\u003c/li\u003e\n\u003cli\u003eTiming, enumeration, or oracle-style attacks only where the report demonstrates tangible security or privacy impact\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOut-of-Scope\u003c/h3\u003e\n\n\u003cp\u003eThe following are out of scope unless the report demonstrates a separate Keeper product vulnerability that creates meaningful additional impact:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSpam or Email Spoofing\u003c/li\u003e\n\u003cli\u003eIssues requiring local compromise of the victim’s device\u003c/li\u003e\n\u003cli\u003eIssues requiring keylogging, malware, malicious local scripts, malicious browser extensions, or arbitrary code execution on the victim’s system\u003c/li\u003e\n\u003cli\u003eIssues requiring a full compromise of the operating system\u003c/li\u003e\n\u003cli\u003eIssues requiring admin, root, SYSTEM, physical access, or equivalent privileged access\u003c/li\u003e\n\u003cli\u003eIssues requiring access to an unlocked, already-authenticated, or already-compromised user session\u003c/li\u003e\n\u003cli\u003eIssues requiring possession of credentials, private keys, recovery phrases, tokens, device keys, encryption keys, or other secrets not obtained through the reported vulnerability\u003c/li\u003e\n\u003cli\u003eIssues where the only affected victim is the researcher or the researcher’s own account\u003c/li\u003e\n\u003cli\u003eSelf-XSS or self-impact issues that cannot be triggered against another user or tenant\u003c/li\u003e\n\u003cli\u003eSocial engineering, phishing, user deception, or attacks that depend primarily on tricking a user into unsafe behavior\u003c/li\u003e\n\u003cli\u003eAttacks that depend on a compromised account, malicious insider, intentionally misconfigured environment, or customer-controlled insecure configuration\u003c/li\u003e\n\u003cli\u003eIssues involving legacy, unsupported, or out-of-date versions of Keeper applications\u003c/li\u003e\n\u003cli\u003eRate limit testing\u003c/li\u003e\n\u003cli\u003eReports based primarily on automated scanner output without validated exploitability and real-world impact\u003c/li\u003e\n\u003cli\u003eAI-generated or low-quality reports that do not demonstrate a real exploit path and material impact\u003c/li\u003e\n\u003cli\u003eTheoretical weaknesses, best-practice recommendations, missing headers, version disclosures, or informational findings without a demonstrated path to meaningful security impact\u003c/li\u003e\n\u003cli\u003eIssues on the Gateway, Automator, SSO Connect, or other hosted services that require physical access\u003c/li\u003e\n\u003cli\u003eAny kind of attack where the only victim is yourself, including self-XSS of a profile picture or information that does not show anywhere else. You must provably show that the attack can affect another user, customer, tenant, or Keeper-managed system.\u003c/li\u003e\n\u003cli\u003eAny Keeper domain, subdomain, product, service, or property not explicitly listed in the Targets section\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eTriage Guidance\u003c/h2\u003e\n\n\u003cp\u003eBugcrowd triage should only escalate reports that include a realistic exploit path, sufficient reproduction steps, and demonstrated security impact aligned with the program’s accepted vulnerability categories.\u003c/p\u003e\n\n\u003cp\u003eReports should be closed as out of scope, not applicable, or informational when they rely primarily on excluded assumptions, do not demonstrate P1/P2-level impact, or fail to show how an attacker could realistically exploit the issue against another user, customer, tenant, or Keeper-managed system.\u003c/p\u003e\n\n\u003cp\u003eSubmissions lacking detailed exploitation steps, validated impact, and a real-world attack scenario are not eligible for reward.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eDocumentation on the Keeper platform is linked below:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eEnterprise Platform Guide: \u003ca href=\"https://docs.keeper.io/enterprise-guide/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.keeper.io/enterprise-guide/\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eEncryption and Security Model: \u003ca href=\"https://docs.keeper.io/enterprise-guide/keeper-encryption-model\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.keeper.io/enterprise-guide/keeper-encryption-model\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eEnd-User Guides: \u003ca href=\"https://docs.keeper.io/user-guides/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.keeper.io/user-guides/\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eKeeper SSO Connect Cloud Guide: \u003ca href=\"https://docs.keeper.io/sso-connect-cloud/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.keeper.io/sso-connect-cloud/\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eKeeper SSO Connect On-Prem Guide: \u003ca href=\"https://docs.keeper.io/sso-connect-guide/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.keeper.io/sso-connect-guide/\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eKeeper Secrets Manager: \u003ca href=\"https://docs.keeper.io/secrets-manager/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.keeper.io/secrets-manager/\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eKeeper Connection Manager: \u003ca href=\"https://docs.keeper.io/keeper-connection-manager/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.keeper.io/keeper-connection-manager/\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eKeeperPAM: \u003ca href=\"https://docs.keeper.io/pam/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.keeper.io/pam/\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eKeeperDB: \u003ca href=\"https://docs.keeper.io/en/keeperpam/privileged-access-manager/keeperdb\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://docs.keeper.io/en/keeperpam/privileged-access-manager/keeperdb\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":"\u003cp\u003e\u0026lt;b\u0026gt;This bounty requires explicit permission to disclose the results of a submission.\u0026lt;/b\u0026gt;\u003c/p\u003e"},"scope":[{"id":"613bf79e-8b76-4b65-8cfb-6c6229e9f18b","name":"In Scope","targets":[{"id":"722a6284-f0b4-4cdc-a872-e2507181de87","uri":"https://www.keepersecurity.com/download.html","name":"Keeper Browser Extension (Chrome, Safari, Firefox, Edge)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6f6a7471-fa8d-4a11-93c2-cc85e7d6ab9b","sortOrder":0},"sortOrder":0,"tags":[{"id":"59791207-9cf4-4498-b5e1-510fee95dc40","name":"Browser Extension","targetId":"722a6284-f0b4-4cdc-a872-e2507181de87"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"722a6284-f0b4-4cdc-a872-e2507181de87"}],"recentChangeFlags":null},{"id":"e1737154-3eab-4fe9-a091-415b0c6e975d","uri":"https://www.keepersecurity.com/download.html","name":"Keeper Desktop App for Mac, PC, Linux","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"91cef387-1f77-46d6-853d-ba0c842de6a7","sortOrder":1},"sortOrder":1,"tags":[{"id":"47f8649b-7612-4d6d-bb41-c0078e628292","name":"Electron","targetId":"e1737154-3eab-4fe9-a091-415b0c6e975d"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"e1737154-3eab-4fe9-a091-415b0c6e975d"},{"id":"fc8162a2-8e37-4a27-8cbd-3b40e7799f4e","name":"Desktop Application Testing","targetId":"e1737154-3eab-4fe9-a091-415b0c6e975d"}],"recentChangeFlags":null},{"id":"47ca4080-8d52-464d-b7a6-55d1e3ca7ac6","uri":"https://keepersecurity.com/vault","name":"Keeper Web Vault (US, EU, AU, CA, JP, GovCloud)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"fdcb0e6c-026f-422a-8262-1bd66463895b","sortOrder":2},"sortOrder":2,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"47ca4080-8d52-464d-b7a6-55d1e3ca7ac6"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"47ca4080-8d52-464d-b7a6-55d1e3ca7ac6"}],"recentChangeFlags":null},{"id":"88dbd834-156d-4371-9baf-132df11e4b3c","uri":"https://www.keepersecurity.com/download.html","name":"Keeper for iOS","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b4836511-5f9f-412f-a335-6d4e89d4dd8c","sortOrder":3},"sortOrder":3,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"88dbd834-156d-4371-9baf-132df11e4b3c"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"88dbd834-156d-4371-9baf-132df11e4b3c"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"88dbd834-156d-4371-9baf-132df11e4b3c"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"88dbd834-156d-4371-9baf-132df11e4b3c"},{"id":"cc05697c-58bf-4b7b-a2b5-2ba0ead3270b","name":"Binary Analysis","targetId":"88dbd834-156d-4371-9baf-132df11e4b3c"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"88dbd834-156d-4371-9baf-132df11e4b3c"}],"recentChangeFlags":null},{"id":"049b7438-4c46-4e18-819a-080d4ab2b3ee","uri":"https://play.google.com/store/apps/details?id=com.callpod.android_apps.keeper\u0026hl=en_US\u0026gl=US","name":"Keeper for Android","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ac087d0f-28ee-4116-bca9-b776ff168728","sortOrder":4},"sortOrder":4,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"049b7438-4c46-4e18-819a-080d4ab2b3ee"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"049b7438-4c46-4e18-819a-080d4ab2b3ee"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"049b7438-4c46-4e18-819a-080d4ab2b3ee"},{"id":"cc05697c-58bf-4b7b-a2b5-2ba0ead3270b","name":"Binary Analysis","targetId":"049b7438-4c46-4e18-819a-080d4ab2b3ee"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"049b7438-4c46-4e18-819a-080d4ab2b3ee"}],"recentChangeFlags":null},{"id":"4828e378-03c0-41e5-a6cf-4ee3fad33c4b","uri":"https://keepersecurity.com/password-manager-free-trial.html","name":"Keeper Enterprise","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"43849609-399b-41f5-8d8c-09c722d338d0","sortOrder":5},"sortOrder":5,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"4828e378-03c0-41e5-a6cf-4ee3fad33c4b"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"4828e378-03c0-41e5-a6cf-4ee3fad33c4b"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"4828e378-03c0-41e5-a6cf-4ee3fad33c4b"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"4828e378-03c0-41e5-a6cf-4ee3fad33c4b"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4828e378-03c0-41e5-a6cf-4ee3fad33c4b"}],"recentChangeFlags":null},{"id":"323ad4a6-efa0-4bc7-b304-ef52dba1b902","uri":"https://docs.keeper.io/en/keeperpam","name":"KeeperPAM Privileged Access Manager","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b64d6514-e7a4-4fc3-891b-3c38f974c841","sortOrder":6},"sortOrder":6,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"323ad4a6-efa0-4bc7-b304-ef52dba1b902"},{"id":"52565107-4b96-4b40-a1f7-873d38c7fc5f","name":"SSH","targetId":"323ad4a6-efa0-4bc7-b304-ef52dba1b902"}],"recentChangeFlags":null},{"id":"0aaccfca-4584-4235-81fa-ad25e94a88d8","uri":"https://docs.keeper.io/kcm","name":"Keeper Connection Manager (KCM)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7741f61a-265a-4bf1-9126-845ce401b013","sortOrder":7},"sortOrder":7,"tags":[{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"0aaccfca-4584-4235-81fa-ad25e94a88d8"},{"id":"80ac7b70-7adf-4684-ab9b-e7f0362596fc","name":"Dockerfile","targetId":"0aaccfca-4584-4235-81fa-ad25e94a88d8"},{"id":"a5a8125d-2e24-4979-a994-d67089f0909b","name":"Apache Tomcat","targetId":"0aaccfca-4584-4235-81fa-ad25e94a88d8"},{"id":"db761f56-c8db-4736-a909-4219e471ea2c","name":"Apache Guacamole","targetId":"0aaccfca-4584-4235-81fa-ad25e94a88d8"}],"recentChangeFlags":null},{"id":"f5029181-8a47-460f-9a25-63de72d0d2b3","uri":"https://docs.keeper.io/en/keeperpam/secrets-manager/overview","name":"Keeper Secrets Manager SDK","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6a260f5a-3c90-46ab-ab4c-fd69e12e7b2d","sortOrder":8},"sortOrder":8,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"f5029181-8a47-460f-9a25-63de72d0d2b3"},{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"f5029181-8a47-460f-9a25-63de72d0d2b3"},{"id":"1f10e73e-4eef-42c1-ba6b-6df69f8dc8fa","name":"Rust","targetId":"f5029181-8a47-460f-9a25-63de72d0d2b3"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"f5029181-8a47-460f-9a25-63de72d0d2b3"}],"recentChangeFlags":null},{"id":"30aac6ed-568d-4eed-83d7-e2e50fff3ec1","uri":"https://keepersecurity.com/console","name":"Keeper Endpoint Privilege Manager","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"06ad9795-e6ab-42cf-ac2e-a660af24f815","sortOrder":9},"sortOrder":9,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"30aac6ed-568d-4eed-83d7-e2e50fff3ec1"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"30aac6ed-568d-4eed-83d7-e2e50fff3ec1"},{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"30aac6ed-568d-4eed-83d7-e2e50fff3ec1"},{"id":"c5df6ad0-33b4-40ac-b6dd-8d4038997d40","name":"macOS","targetId":"30aac6ed-568d-4eed-83d7-e2e50fff3ec1"}],"recentChangeFlags":null},{"id":"94405a63-f8e6-40ca-8b72-f789765df793","uri":"https://keepersecurity.com/console","name":"Keeper Admin Console (US, EU, AU, CA, JP, GovCloud)","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e9a09b49-9b2e-431c-a36f-e40e90a82ac2","sortOrder":10},"sortOrder":10,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"94405a63-f8e6-40ca-8b72-f789765df793"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"94405a63-f8e6-40ca-8b72-f789765df793"}],"recentChangeFlags":null},{"id":"332cb0c3-65ec-4f99-be40-2977e70883db","uri":"https://keepersecurity.com","name":"Keeper Security Website","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a1257b5d-10b2-4c21-b330-b7bd9ae3b657","sortOrder":11},"sortOrder":11,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"332cb0c3-65ec-4f99-be40-2977e70883db"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"332cb0c3-65ec-4f99-be40-2977e70883db"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"332cb0c3-65ec-4f99-be40-2977e70883db"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"332cb0c3-65ec-4f99-be40-2977e70883db"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"332cb0c3-65ec-4f99-be40-2977e70883db"}],"recentChangeFlags":null},{"id":"f6c88865-10e9-4ca7-a1fb-f342062581c8","uri":"https://www.keepersecurity.com/download.html?t=db","name":"KeeperDB","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e43acedd-06a7-4d50-b17b-9776f6a28c47","sortOrder":12},"sortOrder":12,"tags":[{"id":"fc8162a2-8e37-4a27-8cbd-3b40e7799f4e","name":"Desktop Application Testing","targetId":"f6c88865-10e9-4ca7-a1fb-f342062581c8"}],"recentChangeFlags":null},{"id":"a3840ed2-8498-416a-8253-43f531ecf955","uri":"https://docs.keeper.io/keeper-bridge/","name":"Keeper AD / LDAP Bridge","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"159078ed-fc58-43ff-8c53-f60bca4dd708","sortOrder":13},"sortOrder":13,"tags":[{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"a3840ed2-8498-416a-8253-43f531ecf955"}],"recentChangeFlags":null},{"id":"0b79367b-5bad-4827-a267-f5aa2c9def0a","uri":"https://docs.keeper.io/en/keeperpam/privileged-access-manager/getting-started/gateways","name":"Keeper Gateway","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d3aa0d57-cba7-4a51-8dbb-84b6be262bae","sortOrder":14},"sortOrder":14,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"0b79367b-5bad-4827-a267-f5aa2c9def0a"},{"id":"16818e15-ac0f-4e76-999b-8b6a87db2837","name":"Docker","targetId":"0b79367b-5bad-4827-a267-f5aa2c9def0a"}],"recentChangeFlags":null},{"id":"be87c24b-a166-4fa9-9e49-a5835246071c","uri":"https://docs.keeper.io/sso-connect-cloud/","name":"SSO Connect Cloud and Automator Service","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f26258c2-2f22-466c-b9c3-5de7df850fe0","sortOrder":15},"sortOrder":15,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"be87c24b-a166-4fa9-9e49-a5835246071c"},{"id":"b9ed9d9d-ddfd-4f85-9085-fec1689e6d06","name":"SAML","targetId":"be87c24b-a166-4fa9-9e49-a5835246071c"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"be87c24b-a166-4fa9-9e49-a5835246071c"}],"recentChangeFlags":null},{"id":"228cb6b8-97f7-4d30-aa47-73f3364cb24e","uri":"https://docs.keeper.io/sso-connect-guide/","name":"SSO Connect On-Prem","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c0504a23-3f6a-4ad9-86fd-6f7f64d852ca","sortOrder":16},"sortOrder":16,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"228cb6b8-97f7-4d30-aa47-73f3364cb24e"},{"id":"b9ed9d9d-ddfd-4f85-9085-fec1689e6d06","name":"SAML","targetId":"228cb6b8-97f7-4d30-aa47-73f3364cb24e"}],"recentChangeFlags":null},{"id":"8f7e060e-8986-4784-b26f-0e8057349565","uri":"https://docs.keeper.io/en/keeperpam/commander-cli/overview","name":"Keeper Commander CLI/SDK","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1f7c16cb-4a0a-4375-9061-6c5a959168dd","sortOrder":17},"sortOrder":17,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"8f7e060e-8986-4784-b26f-0e8057349565"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"8f7e060e-8986-4784-b26f-0e8057349565"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"8f7e060e-8986-4784-b26f-0e8057349565"}],"recentChangeFlags":null},{"id":"6de33998-dde0-4455-8b10-8e9f6942b8cc","uri":"https://www.microsoft.com/en-us/p/keeperchat/9pdqtcpn4kxn#activetab=pivot:overviewtab","name":"KeeperChat for Windows","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0b251f1b-d38d-42c7-b098-9e1fe8b8f88d","sortOrder":18},"sortOrder":18,"tags":[{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"6de33998-dde0-4455-8b10-8e9f6942b8cc"},{"id":"cc05697c-58bf-4b7b-a2b5-2ba0ead3270b","name":"Binary Analysis","targetId":"6de33998-dde0-4455-8b10-8e9f6942b8cc"}],"recentChangeFlags":null},{"id":"eacdcf14-c4bb-418a-b9c5-ef0fe980d8e6","uri":"https://apps.apple.com/app/id1216446440","name":"KeeperChat for iOS","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"963398fd-f4cb-4ac6-a1f7-859015295e98","sortOrder":19},"sortOrder":19,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"eacdcf14-c4bb-418a-b9c5-ef0fe980d8e6"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"eacdcf14-c4bb-418a-b9c5-ef0fe980d8e6"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"eacdcf14-c4bb-418a-b9c5-ef0fe980d8e6"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"eacdcf14-c4bb-418a-b9c5-ef0fe980d8e6"},{"id":"cc05697c-58bf-4b7b-a2b5-2ba0ead3270b","name":"Binary Analysis","targetId":"eacdcf14-c4bb-418a-b9c5-ef0fe980d8e6"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"eacdcf14-c4bb-418a-b9c5-ef0fe980d8e6"}],"recentChangeFlags":null},{"id":"40c80563-488a-49e6-b9ce-6835a4c71b71","uri":"https://play.google.com/store/apps/details?id=com.keepersecurity.chat\u0026hl=en_US\u0026gl=US","name":"KeeperChat for Android","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d3a04f97-3234-4aaa-829f-8edc289e23c1","sortOrder":20},"sortOrder":20,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"40c80563-488a-49e6-b9ce-6835a4c71b71"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"40c80563-488a-49e6-b9ce-6835a4c71b71"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"40c80563-488a-49e6-b9ce-6835a4c71b71"},{"id":"cc05697c-58bf-4b7b-a2b5-2ba0ead3270b","name":"Binary Analysis","targetId":"40c80563-488a-49e6-b9ce-6835a4c71b71"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"40c80563-488a-49e6-b9ce-6835a4c71b71"}],"recentChangeFlags":null},{"id":"ed04b2c7-1883-438e-9448-e1bbb281dc23","uri":"https://apps.apple.com/us/app/keeperchat/id1273303729?mt=12","name":"KeeperChat for Mac","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c731e81c-2e8d-4ebc-a7f4-8c77ca6d47f5","sortOrder":21},"sortOrder":21,"tags":[{"id":"c5df6ad0-33b4-40ac-b6dd-8d4038997d40","name":"macOS","targetId":"ed04b2c7-1883-438e-9448-e1bbb281dc23"},{"id":"cc05697c-58bf-4b7b-a2b5-2ba0ead3270b","name":"Binary Analysis","targetId":"ed04b2c7-1883-438e-9448-e1bbb281dc23"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"53747311-53b1-4ea8-b310-92e00ac27659","p1MaxCents":1000000,"p1MinCents":600000,"p2MaxCents":500000,"p2MinCents":250000,"p3MaxCents":150000,"p3MinCents":50000,"p4MaxCents":30000,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":2000000},"descriptionHtml":null,"rewardRangeData":{"1":{"min":6000,"max":10000},"2":{"min":2500,"max":5000},"3":{"min":500,"max":1500},"4":{"min":0,"max":300},"5":{"min":null,"max":null},"programMax":20000},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"0931c43d-9978-457e-881a-81460e5310a8","code":"keepersecurity","state":"in_progress","endsAt":null,"bountyId":"26c84d6c-67cb-400d-a89e-5aae7b797843","startsAt":"2018-04-10T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/8c3d/26ef/db70bc60/8f6dae1d003d325e724de4cfef999810_Keeper_Yellow_Logo.png","logoBackgroundColor":"#000000","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2018-04-10T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/keepersecurity","changelogs":"/engagements/keepersecurity/changelog","submissions":null,"announcements":"/engagements/keepersecurity/announcements","hallOfFame":"/engagements/keepersecurity/hall_of_fames","crowdstream":"/engagements/keepersecurity/crowdstream"},"announcementsCount":7,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/keepersecurity/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=keepersecurity\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/keepersecurity/engagement_subscribers","engagementChangelogsUrl":"/engagements/keepersecurity/changelog","publishedAt":"2026-05-19T01:37:38.093Z","engagementChangelogUrl":"/engagements/keepersecurity/changelog/0c2e8a25-07ad-4b8d-8846-a8a763faad93","createUserFeedbacksUrl":"/engagements/keepersecurity/feedbacks","engagementCrowdstreamUrl":"/engagements/keepersecurity/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}