alasco-gmbh-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
4
In Scope
15
Out of Scope
In-Scope Assets (4)
Out-of-Scope Assets (15)
AssetCategoryBounty
Alasco will not provide access credentials to any system, not for testing and also not for issue validation.OTHERYes
All other domains or subdomains not listed in the above list of 'Scopes'.OTHERYes
Attention: Third-party managed infrastructure (e.g. HubSpot, Salesforce, or other SaaS platforms) where Alasco has no ability to remediate vulnerabilities at the infrastructure or platform level, regardless of the subdomain.OTHERYes
However, any vulnerability discovered in a system or service that requires a login to access is outside the scope of this program.OTHERYes
Please note that all non-authenticated areas of our systems are in scope for this program. This means that any vulnerability discovered in a system or service that does not require a login to access is eligible for a reward.OTHERYes
alasco.comOTHERYes
alasco.deOTHERYes
explore.alasco.comOTHERYes
explore.alasco.deOTHERYes
lp.alasco.comOTHERYes
lp.alasco.deOTHERYes
support.alasco.comOTHERYes
support.alasco.deOTHERYes
www.alasco.comOTHERYes
www.alasco.deOTHERYes
Scope Changes (58)
Jul 22, 2026
ChangeAssetCategoryScopeTime
Addedwww.alasco.comOTHEROut of Scope09:26
Addedalasco.comOTHEROut of Scope09:26
Addedlp.alasco.deOTHEROut of Scope09:26
Addedlp.alasco.comOTHEROut of Scope09:26
Addedsupport.alasco.deOTHEROut of Scope09:26
Addedsupport.alasco.comOTHEROut of Scope09:26
Addedattention: third-party managed infrastructure (e.g. hubspot, salesforce, or other saas platforms) where alasco has no ability to remediate vulnerabilities at the infrastructure or platform level, regardless of the subdomainOTHEROut of Scope09:26
Addedwww.alasco.comOTHEROut of Scope09:26
Addedsupport.alasco.deOTHEROut of Scope09:26
Addedlp.alasco.deOTHEROut of Scope09:26
Addedlp.alasco.comOTHEROut of Scope09:26
Addedsupport.alasco.comOTHEROut of Scope09:26
Addedalasco.comOTHEROut of Scope09:26
Addedattention: third-party managed infrastructure (e.g. hubspot, salesforce, or other saas platforms) where alasco has no ability to remediate vulnerabilities at the infrastructure or platform level, regardless of the subdomainOTHEROut of Scope09:26
Feb 25, 2026
ChangeAssetCategoryScopeTime
Added*.alasco.rocksWILDCARDIn Scope19:09
Addedhowever, any vulnerability discovered in a system or service that requires a login to access is outside the scope of this programOTHEROut of Scope19:09
Addedapp.alasco.deURLIn Scope19:09
Addedapi.alasco.deURLIn Scope19:09
Addedall other domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope19:09
Addedexplore.alasco.comURLOut of Scope19:09
Addedalasco.deURLOut of Scope19:09
Addedalasco will not provide access credentials to any system, not for testing and also not for issue validationOTHEROut of Scope19:09
Added*.alasco.deWILDCARDIn Scope19:09
Addedexplore.alasco.deURLOut of Scope19:09
Addedwww.alasco.deURLOut of Scope19:09
Addedplease note that all non-authenticated areas of our systems are in scope for this program. this means that any vulnerability discovered in a system or service that does not require a login to access is eligible for a rewardOTHEROut of Scope19:09
Feb 22, 2026
ChangeAssetCategoryScopeTime
Added*.alasco.deWILDCARDIn Scope00:52
Addedexplore.alasco.comURLOut of Scope00:52
Addedexplore.alasco.deURLOut of Scope00:52
Addedalasco.deURLOut of Scope00:52
Addedhowever, any vulnerability discovered in a system or service that requires a login to access is outside the scope of this programOTHEROut of Scope00:52
Addedapp.alasco.deURLIn Scope00:52
Added*.alasco.rocksWILDCARDIn Scope00:52
Addedall other domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope00:52
Addedwww.alasco.deURLOut of Scope00:52
Addedplease note that all non-authenticated areas of our systems are in scope for this program. this means that any vulnerability discovered in a system or service that does not require a login to access is eligible for a rewardOTHEROut of Scope00:52
Addedalasco will not provide access credentials to any system, not for testing and also not for issue validationOTHEROut of Scope00:52
Addedapi.alasco.deURLIn Scope00:52
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removedapp.alasco.deURLIn Scope21:40
Removedapi.alasco.deURLIn Scope21:40
Removed*.alasco.deOTHERIn Scope21:40
Removed*.alasco.rocksOTHERIn Scope21:40
Removedall other domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope21:40
Removedexplore.alasco.comOTHEROut of Scope21:40
Removedexplore.alasco.deOTHEROut of Scope21:40
Removedwww.alasco.deOTHEROut of Scope21:40
Removedalasco.deOTHEROut of Scope21:40
Removedplease note that all non-authenticated areas of our systems are in scope for this program. this means that any vulnerability discovered in a system or service that does not require a login to access is eligible for a rewardOTHEROut of Scope21:40
Removedhowever, any vulnerability discovered in a system or service that requires a login to access is outside the scope of this programOTHEROut of Scope21:40
Removedalasco will not provide access credentials to any system, not for testing and also not for issue validationOTHEROut of Scope21:40
Addedexplore.alasco.comOTHEROut of Scope00:33
Addedexplore.alasco.deOTHEROut of Scope00:33
Addedwww.alasco.deOTHEROut of Scope00:33
Addedalasco.deOTHEROut of Scope00:33
Addedplease note that all non-authenticated areas of our systems are in scope for this program. this means that any vulnerability discovered in a system or service that does not require a login to access is eligible for a rewardOTHEROut of Scope00:33
Addedhowever, any vulnerability discovered in a system or service that requires a login to access is outside the scope of this programOTHEROut of Scope00:33
Addedalasco will not provide access credentials to any system, not for testing and also not for issue validationOTHEROut of Scope00:33
Addedall other domains or subdomains not listed in the above list of 'scopes'OTHEROut of Scope00:33