{"id":"b3499ffa-739f-4d0f-aa63-ffc1cde0b77d","engagementId":"b36cadef-c9c0-4a3d-9e78-a499b9e62192","data":{"brief":{"id":"4076dbeb-b56c-42f0-92a4-b165a413d712","name":"StrongDM Vulnerability Disclosure Engagement","tagline":"Policy-based Zero Trust PAM.","description":"\u003cp\u003eStrongDM is a business-to-business (B2B) SaaS provider, and the focus of this vulnerability disclosure program is to provide our customers and prospects with an avenue for securely report potential vulnerabilities to us. That being said, StrongDM looks forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe.\u003c/p\u003e\n\n\u003ch1\u003eServices Agreement\u003c/h1\u003e\n\n\u003cp\u003eWhile all of the StrongDM Services Agreement must be adhered to, any submissions by Customers or by third-parties on behalf of Customers or Prospects of StrongDM must comply with \u003ca href=\"https://www.strongdm.com/legal/services-agreement#:%7E:text=of%20such%20Databases.-,2.4,-Customer%20agrees%20not\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSection 2.4\u003c/a\u003e of the StrongDM Services Agreement\u003c/p\u003e\n\n\u003ch1\u003eResponse \u0026amp; Remediation Targets\u003c/h1\u003e\n\n\u003cp\u003eStrongDM will make a best effort to meet the following SLAs for hackers participating in our program:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eType of Response\u003c/th\u003e\n\u003cth\u003eSLA in business days\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eFirst Response\u003c/td\u003e\n\u003ctd\u003e3 days\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eTime to Triage\u003c/td\u003e\n\u003ctd\u003e3 days\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eTime to Resolution\u003c/td\u003e\n\u003ctd\u003edepends on severity and complexity\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003ePlease note that the severity rating for a reported vulnerability may be adjusted by StrongDM in line with our Vulnerability Management Program. We’ll try to keep you informed about our progress throughout the remediation process.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of StrongDM not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to StrongDM, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePotential post-exploitation scenarios: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity\u003c/li\u003e\n\u003cli\u003eYou are testing on production. Behavior that compromises the stability and integrity of the target(s) is out of scope.\n\n\u003cul\u003e\n\u003cli\u003e For example, do not target other users' data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS attack, and/or compromise any target's ability to function for other users. If you believe that you have found a vulnerability of this nature, please stop further testing and report it\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eReports must contain a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eThe applications within scope are publicly accessible\u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eCredentials are not provided for testing. Please do not create any accounts. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eTo support your testing, we’ve highlighted several key areas of interest. While we ask that you report any efforts related to these areas, please note that testing is not limited to them. Submissions outside of these focus areas are equally welcomed and appreciated.\u003c/p\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cp\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\u003cbr\u003e\ne.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/p\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003eSubmissions related to leaked or exposed credentials (e.g., dark web forums, credential dumps) will be reviewed on a case-by-case basis and may qualify for points-based compensation only. The use of any leaked credentials during testing is strictly prohibited and may result in disqualification from the bounty program.\u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing or flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eALL forms of social Engineering\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via our \u003ca href=\"https://bugcrowd-support.freshdesk.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFreshdesk Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":"\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e"},"scope":[{"id":"3eaa20a5-10ba-43a2-a0ec-b9e4e6303acc","name":"In Scope","targets":[{"id":"641f6b5f-ccba-48d9-aad6-68cd96ed23a0","uri":"https://app.strongdm.com/","name":"https://app.strongdm.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"67dcafb4-01b5-4516-b909-2f7368bf8fba","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"641f6b5f-ccba-48d9-aad6-68cd96ed23a0"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"641f6b5f-ccba-48d9-aad6-68cd96ed23a0"}],"recentChangeFlags":null},{"id":"8400a07d-10c9-4912-bb40-2dfc895cb8b5","uri":"https://github.com/strongdm/strongdm-sdk-java","name":"StrongDM Java SDK","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9111674b-fda6-465d-a66d-c6db726bf30b","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"8400a07d-10c9-4912-bb40-2dfc895cb8b5"}],"recentChangeFlags":null},{"id":"16965199-a903-41c6-804c-6212a6832527","uri":"https://github.com/strongdm/strongdm-sdk-ruby","name":"StrongDM Ruby SDK","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0c97bb09-6ae4-4a0a-94b8-d832ca3d29a6","sortOrder":2},"sortOrder":2,"tags":[{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"16965199-a903-41c6-804c-6212a6832527"}],"recentChangeFlags":null},{"id":"896f8a3a-18fc-46ae-b945-824cc07c969e","uri":"https://github.com/strongdm/strongdm-sdk-python","name":"StrongDM Python SDK","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5d16fb7a-73a1-4d5f-8976-3b04be48803b","sortOrder":3},"sortOrder":3,"tags":[{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"896f8a3a-18fc-46ae-b945-824cc07c969e"}],"recentChangeFlags":null},{"id":"2352b517-cd4c-4ec0-93c7-263b957d3ea3","uri":"https://github.com/strongdm/strongdm-sdk-go","name":"StrongDM Go SDK","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1a4abdda-1bc2-4c27-a4ba-5705a9333e89","sortOrder":4},"sortOrder":4,"tags":[{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"2352b517-cd4c-4ec0-93c7-263b957d3ea3"}],"recentChangeFlags":null},{"id":"afd75869-dda0-4f22-aa6e-911506abcb7c","uri":"https://quay.io/repository/sdmrepo/relay?tab=info","name":"StrongDM Gateway Docker/Kuberneters/Fargate Relay Container Image","category":"network","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"bf081c54-8e39-499d-b60a-ffbf06c51c0e","sortOrder":5},"sortOrder":5,"tags":[{"id":"16818e15-ac0f-4e76-999b-8b6a87db2837","name":"Docker","targetId":"afd75869-dda0-4f22-aa6e-911506abcb7c"},{"id":"e82bba17-848b-4f2b-a2a5-58d2a83530d4","name":"Kubernetes","targetId":"afd75869-dda0-4f22-aa6e-911506abcb7c"}],"recentChangeFlags":null},{"id":"8a375267-79cd-42b8-977a-6b549e221172","uri":"https://docs.strongdm.com/users/client/windows","name":"SDM Client - Windows (sdm.exe)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c62130f5-3cc3-4adb-8725-24dddeb1b2b8","sortOrder":6},"sortOrder":6,"tags":[{"id":"9c63a0f4-0db6-40da-85f0-65d0aa72bfbe","name":"Windows","targetId":"8a375267-79cd-42b8-977a-6b549e221172"}],"recentChangeFlags":null},{"id":"fd21a497-369f-4b5d-8527-e76aa0c8ca35","uri":"https://docs.strongdm.com/users/client/macos","name":"SDM Client - macOS (sdm.app)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e43cd09d-946c-42ba-b8ed-98627945af12","sortOrder":7},"sortOrder":7,"tags":[{"id":"c5df6ad0-33b4-40ac-b6dd-8d4038997d40","name":"macOS","targetId":"fd21a497-369f-4b5d-8527-e76aa0c8ca35"}],"recentChangeFlags":null},{"id":"48fb90f8-4ce8-4429-a5be-76adc051749e","uri":"https://docs.strongdm.com/users/client/linux","name":"SDM Gateway - *nix application","category":"network","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e0a9b3de-dc6b-472f-a512-754651200db0","sortOrder":8},"sortOrder":8,"tags":[{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"48fb90f8-4ce8-4429-a5be-76adc051749e"},{"id":"69f77df1-ad5b-4eef-b747-b6190b9cc002","name":"UNIX","targetId":"48fb90f8-4ce8-4429-a5be-76adc051749e"}],"recentChangeFlags":null},{"id":"4830dc56-27d8-45ff-8205-a3ecf5101b2a","uri":"","name":"*.sdm.network","category":"network","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"202f084f-01c2-49a4-ab9a-325d34825372","sortOrder":9},"sortOrder":9,"tags":[{"id":"057eb8bf-b949-4f16-95f2-5bd83851a78d","name":"Network Testing","targetId":"4830dc56-27d8-45ff-8205-a3ecf5101b2a"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch2\u003eDocumentation\u003c/h2\u003e\n\n\u003cp\u003eAvailable documentation can be found \u003ca href=\"https://docs.strongdm.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. \u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"9fbf35ee-3b40-4273-b8d8-7713a30b5ef1","name":"Out of Scope","targets":[{"id":"a3a9c8bf-dafd-4f24-a592-96d75ade4237","uri":"https://www.strongdm.com","name":"StrongDM Corporate Page","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4acbb73b-bdaf-4c62-872a-0ccf6b5da74c","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"9f54668f-8543-4445-a367-b32272c0d562","uri":"https://www.strongdm.com/signup","name":"StrongDM Trial Sign Up","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"935dbc84-92d6-47e0-82e3-8ba75ec82ff2","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"a2734937-17b7-4a05-bab8-47041cdf6d2a","uri":"https://docs.strongdm.com","name":"StrongDM Documentation","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ce10a741-8a9e-4bdf-b6d7-c866bc16b517","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"3448db56-5838-4949-9062-1c99e577e011","uri":"https://status.strongdm.com","name":"StrongDM Status Page","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d61d3c2b-0c3f-482c-9bf1-31c3174c53ab","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"643eb4ab-8792-4e7f-877a-60d3dc2b009a","uri":"https://security.strongdm.com","name":"StrongDM Security Page","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1cb0f7ca-c3f4-4c31-905e-2dae531a24cd","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"e1ad0843-1c99-45a9-ad5e-92b9106e2f73","uri":"https://help.strongdm.com","name":"StrongDM Help Page","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6c464c88-f9f1-495e-8634-e65571cf6998","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch2\u003eDescriptions\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003edocs.strongdm.com Our Documentation pages are outside the testing scope, and may only be used as reference. No security testing should be done against any docs.strongdm.com pages. \u003c/li\u003e\n\u003cli\u003estatus.strongdm.com Our Status Page site is hosted externally by Atlassian. No security testing should be done against the platform itself. Any security issues found within the platform should be reported directly to \u003ca href=\"https://bugcrowd.com/atlassian\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAtlassian\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003esecurity.strongdm.com Our Security Portal is hosted externally by SafeBase. No security testing should be done against the platform itself. Any security issues found within the platform should be reported directly to security@safebase.io\u003c/li\u003e\n\u003cli\u003ehelp.strongdm.com Our support site is hosted externally by Zendesk. No security testing should be done against the platform itself. Any security issues found within the platform should be reported \u003ca href=\"https://hackerone.com/zendesk\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003edirectly to Zendesk\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"b36cadef-c9c0-4a3d-9e78-a499b9e62192","code":"strongdm","state":"in_progress","endsAt":null,"bountyId":"99b8556b-cee5-4131-ae87-58893b87ffcc","startsAt":"2025-12-02T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/96fa/9361/4887e39e/840fd7bba090b1372e86d766813eec84_strongdm_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-12-02T18:00:02.592Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/strongdm","changelogs":"/engagements/strongdm/changelog","submissions":null,"announcements":"/engagements/strongdm/announcements","hallOfFame":"/engagements/strongdm/hall_of_fames","crowdstream":null},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/strongdm/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=strongdm\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/strongdm/engagement_subscribers","engagementChangelogsUrl":"/engagements/strongdm/changelog","publishedAt":"2026-01-09T19:11:14.712Z","engagementChangelogUrl":"/engagements/strongdm/changelog/b3499ffa-739f-4d0f-aa63-ffc1cde0b77d","createUserFeedbacksUrl":"/engagements/strongdm/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}