Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
msci
1
In Scope
2
Out of Scope
In-Scope Assets (1)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| Any public-facing system owned, operated, or controlled by MSCI, including web applications hosted on those sites. | OTHER | No | - |
Out-of-Scope Assets (2)
| Asset | Category | Bounty | |
|---|---|---|---|
| *.msci.com.ar | WILDCARD | No | |
| https://careers.msci.com/ | URL | No |
Scope Changes (9)
Feb 25, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | any public-facing system owned, operated, or controlled by msci, including web applications hosted on those sites | OTHER | In Scope | 19:20 |
| Added | https://careers.msci.com/ | URL | Out of Scope | 19:20 |
| Added | *.msci.com.ar | WILDCARD | Out of Scope | 19:20 |
Feb 22, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | *.msci.com.ar | WILDCARD | Out of Scope | 00:48 |
| Added | any public-facing system owned, operated, or controlled by msci, including web applications hosted on those sites | OTHER | In Scope | 00:48 |
| Added | https://careers.msci.com/ | URL | Out of Scope | 00:48 |
Feb 21, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | any public-facing system owned, operated, or controlled by msci, including web applications hosted on those sites | OTHER | In Scope | 19:13 |
| Added | https://careers.msci.com/ | URL | Out of Scope | 19:13 |
| Added | *.msci.com.ar | WILDCARD | Out of Scope | 19:13 |