Vulnerability Disclosure Program (VDP)

VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.

ourahealthoy/ouravulnerabilitydisclosureprogram

IntigritiView on Intigriti
RawAI Enhanced
6
In Scope
1
Out of Scope
In-Scope Assets (6)
AssetCategoryBountyQuick Links
*.ouraring.comWILDCARDNo
Any Oura related domainOTHERNo-
Official Oura Ring AccessoriesOTHERNo-
Oura Android AppANDROIDNo-
Oura Ring (Gen 3 to current)HARDWARENo-
Oura iOS AppIOSNo-
Out-of-Scope Assets (1)
AssetCategoryBounty
Services not hosted/owned by OuraOTHERNo
Scope Changes (14)
Jun 2, 2026
ChangeAssetCategoryScopeTime
Added*.ouraring.comWILDCARDIn Scope14:26
Addedoura android appANDROIDIn Scope14:26
Addedoura ios appIOSIn Scope14:26
Addedoura ring (gen 3 to current)HARDWAREIn Scope14:26
Addedany oura related domainOTHERIn Scope14:26
Addedofficial oura ring accessoriesOTHERIn Scope14:26
Addedservices not hosted/owned by ouraOTHEROut of Scope14:26
Added*.ouraring.comWILDCARDIn Scope14:26
Addedoura android appANDROIDIn Scope14:26
Addedoura ios appIOSIn Scope14:26
Addedoura ring (gen 3 to current)HARDWAREIn Scope14:26
Addedany oura related domainOTHERIn Scope14:26
Addedofficial oura ring accessoriesOTHERIn Scope14:26
Addedservices not hosted/owned by ouraOTHEROut of Scope14:26