Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
/engagements/sunrun-vdp-pro
7
In Scope
2
Out of Scope
In-Scope Assets (7)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| https://ai.sunrun.com/ | URL | No | ||
| https://elephant.ai.sunrun.com/ | URL | No | ||
| https://ipa.ai.sunrun.com/ | URL | No | ||
| https://servicetransfer.staging.ai.sunrun.com/ | URL | No | ||
| https://sunrunone.com/dashboard | URL | No | ||
| https://www.affiliates.ai.sunrun.com/ | URL | No | ||
| https://www.valuereport.ai.sunrun.com/ | URL | No |
Out-of-Scope Assets (2)
| Asset | Category | Bounty | |
|---|---|---|---|
| Third-party SaaS services not owned or managed by Sunrun | OTHER | No | |
| Vendor-hosted platforms outside direct Sunrun control | OTHER | No |