Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

msci

HackerOneView on HackerOne
RawAI Enhanced
1
In Scope
2
Out of Scope
In-Scope Assets (1)
AssetCategoryBountyQuick Links
Any public-facing system owned, operated, or controlled by MSCI, including web applications hosted on those sites. OTHERNo-
Out-of-Scope Assets (2)
AssetCategoryBounty
*.msci.com.arWILDCARDNo
https://careers.msci.com/URLNo
Scope Changes (9)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedany public-facing system owned, operated, or controlled by msci, including web applications hosted on those sitesOTHERIn Scope19:20
Addedhttps://careers.msci.com/URLOut of Scope19:20
Added*.msci.com.arWILDCARDOut of Scope19:20
Feb 22, 2026
ChangeAssetCategoryScopeTime
Added*.msci.com.arWILDCARDOut of Scope00:48
Addedany public-facing system owned, operated, or controlled by msci, including web applications hosted on those sitesOTHERIn Scope00:48
Addedhttps://careers.msci.com/URLOut of Scope00:48
Feb 21, 2026
ChangeAssetCategoryScopeTime
Addedany public-facing system owned, operated, or controlled by msci, including web applications hosted on those sitesOTHERIn Scope19:13
Addedhttps://careers.msci.com/URLOut of Scope19:13
Added*.msci.com.arWILDCARDOut of Scope19:13