Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
/engagements/gapinc
11
In Scope
8
Out of Scope
In-Scope Assets (11)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| https://api.gap.com/ | URL | No | ||
| https://api.gap.com/credit_cards/v1/?external_customer_id= | URL | No | ||
| https://apps.apple.com/us/app/gap/id326347260 | IOS | No | - | |
| https://gap.com | URL | No | ||
| https://gap.com/checkout | URL | No | ||
| https://gap.com/shopping-bag | URL | No | ||
| https://play.google.com/store/apps/details?id=com.skava.hybridapp.gap&hl=en_US&gl=US | ANDROID | No | ||
| https://secure-www.gap.com | URL | No | ||
| https://secure-www.gap.com/checkout/place-order/ | URL | No | ||
| https://secure-www.gap.com/checkout/place-order/xapi/place-order-action | URL | No | ||
| https://secure-www.gap.com/checkout/place-order/xapi/update-payment-method-action | URL | No |
Out-of-Scope Assets (8)
| Asset | Category | Bounty | |
|---|---|---|---|
| *.gap.com.mx | URL | No | |
| *.gaptech.com | URL | No | |
| *.liverpool.com.* | URL | No | |
| Intermix | URL | No | |
| Janie & Jack | URL | No | |
| Recruiting - jobs.gapinc.com, careersblog.gapinc.com | URL | No | |
| equality.gapinc.com | URL | No | |
| investors.gapinc.com | URL | No |