{"id":"694d507f-e247-49d3-bafa-98e2cf44c9d2","engagementId":"88742432-aa96-4233-b9cf-693fcb0eb607","data":{"brief":{"id":"b7929ca6-d39c-436c-81a3-9032806e99ed","name":"Umbrella Corporation-Demo VDP","tagline":"Science for a comfortable life!","description":"\u003cp\u003eUmbrella Corporation is dedicated to the ideals of vigilance for our children and the future of global security. We are the world's foremost experts in the areas of bio-medical research, bio-technology, and bio-engineering\u003c/p\u003e\n\n\u003cp\u003eWe take the security of our systems seriously, and we value the security researcher community. The disclosure of security vulnerabilities by security researchers helps us ensure the security and privacy of our users.\u003c/p\u003e\n\n\u003ch2\u003eGuidelines:\u003c/h2\u003e\n\n\u003cp\u003ellama \u003c/p\u003e\n\n\u003cp\u003eTest test \u003c/p\u003e\n\n\u003cp\u003eWe require that all researchers:\u003c/p\u003e\n\n\u003cp\u003eGuidelines\u003cbr\u003e\nMake a every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing;\u003cbr\u003e\nPerform research only within the scope set out below;\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eUse the identified communication channels to report vulnerability information to us; and\u003c/li\u003e\n\u003cli\u003eKeep information about any vulnerabilities you’ve discovered confidential between yourself and Umbrella Corporation.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf you follow these guidelines when reporting an issue to us we commit to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNot institute a civil legal action against you and not support a criminal investigation;\u003c/li\u003e\n\u003cli\u003eWork with you to understand and resolve the issue quickly (confirming the report within 72 hours of submission);\u003c/li\u003e\n\u003cli\u003eRecognize your contribution on our Security Researcher Hall of Fame, if you are the first to report the issue and we make a code or configuration change based on the issue.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThank you for participating, it is your work that will help to keep us secure.\u003cbr\u003e\nllama \u003c/p\u003e","industryTagId":"cee83074-d79a-4eed-8c92-f927b8647c7a","targetsOverview":"\u003ch2\u003eOut of scope\u003c/h2\u003e\n\n\u003cp\u003eAny services hosted by 3rd party providers and services are excluded from scope. \u003c/p\u003e\n\n\u003cp\u003eIn the interest of the safety of our users, staff, the Internet at large and you as the security researcher, the following test types are excluded from scope and not eligible for a reward:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll submissions matching P5 in Bugcrowd's Vulnerability Rating Taxonomy will be marked Wont Fix\u003c/li\u003e\n\u003cli\u003eFindings from physical testing such as office access (e.g. open doors, tailgating)\u003c/li\u003e\n\u003cli\u003eFindings derived primarily from social engineering (e.g. phishing, vishing)\u003c/li\u003e\n\u003cli\u003eFindings from applications or systems not listed in the ‘Targets’ section\u003c/li\u003e\n\u003cli\u003eFunctional, UI and UX bugs and spelling mistakes\u003c/li\u003e\n\u003cli\u003eNetwork level Denial of Service (DoS/DDoS) vulnerabilities\u003c/li\u003e\n\u003cli\u003eXSS\u003c/li\u003e\n\u003cli\u003ellamas\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThings we do not want to see:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePersonally identifiable information of users (PII) that you may have found during your research\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eResponsible Disclosure Guidelines:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eWe will investigate legitimate reports and make every effort to correct any valid vulnerability as quickly as possible. In the spirit of encouraging responsible disclosure and reporting, we will not take legal action against nor ask law enforcement to investigate researchers participating in the program provided their compliance with the following Responsible Disclosure Guidelines:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eProvide full details of the vulnerability, including information needed to reproduce and validate the issue by producing \u003c/li\u003e\n\u003cli\u003eProof of Concept (code, technical demos of vulnerability, or necessary steps needed to demonstrate your finding)\u003c/li\u003e\n\u003cli\u003eMake a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services\u003c/li\u003e\n\u003cli\u003eDo not modify, access, or retain data that does not belong to you\u003c/li\u003e\n\u003cli\u003eDo not disclose any vulnerabilities or their technical details without written permission from Express Scripts\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eSafe Harbor\u003c/h1\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy; \u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls; \u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy;\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003c/p\u003e\n\n\u003cp\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our official channels before going any further.\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"2b4be4e2-a9b3-4f42-acd1-8a630ff5e032","name":"High Priority In-Scope Assets","targets":[{"id":"7b6d652b-bd83-4d17-a9c7-4054ef938584","uri":null,"name":"https://www.umbrella.corp/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"017067fc-8546-45fc-9e86-f67d85edbae0","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"7b6d652b-bd83-4d17-a9c7-4054ef938584"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"7b6d652b-bd83-4d17-a9c7-4054ef938584"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"7b6d652b-bd83-4d17-a9c7-4054ef938584"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7b6d652b-bd83-4d17-a9c7-4054ef938584"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"7b6d652b-bd83-4d17-a9c7-4054ef938584"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"88742432-aa96-4233-b9cf-693fcb0eb607","code":"umbrella-demo-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"986bf6ad-3a11-4e5e-8177-4b3eb5f4061a","startsAt":"2025-10-06T14:42:19Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Biotech","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2fb0/0df9/48187afd/f76c0128f7883fbf6d3628b5aa3598d2_umbrella.jpg","logoBackgroundColor":"#000000","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-10-06T14:42:19.038Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/umbrella-demo-vdp-pro","changelogs":"/engagements/umbrella-demo-vdp-pro/changelog","submissions":null,"announcements":"/engagements/umbrella-demo-vdp-pro/announcements","hallOfFame":"/engagements/umbrella-demo-vdp-pro/hall_of_fames","crowdstream":"/engagements/umbrella-demo-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":true,"serviceLevel":"Platform","submitReportUrl":"/engagements/umbrella-demo-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=umbrella-demo-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/umbrella-demo-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/umbrella-demo-vdp-pro/changelog","publishedAt":"2026-09-09T02:30:28.469Z","engagementChangelogUrl":"/engagements/umbrella-demo-vdp-pro/changelog/694d507f-e247-49d3-bafa-98e2cf44c9d2","createUserFeedbacksUrl":"/engagements/umbrella-demo-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/umbrella-demo-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}