infomaniak-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
40
In Scope
14
Out of Scope
In-Scope Assets (40)
AssetCategoryBountyQuick Links
*.kchat.infomaniak.comURLYes
*.kdrive.infomaniak.comURLYes
*.vod2.infomaniak.comURLYes
5k8vrbdyje.infomaniak.siteURLYes
academy.infomaniak.comURLYes
admin2.infomaniak.comURLYes
ai-tools.infomaniak.comANDROIDYes
api.infomaniak.comURLYes
calendar.infomaniak.comURLYes
chk.infomaniak.comURLYes
contacts.infomaniak.comURLYes
developer.infomaniak.comURLYes
etickets.infomaniak.comURLYes
euria.infomaniak.comURLYes
fv3lfbdyjh.infomaniak.siteURLYes
https://apps.apple.com/app/infomaniak-kdrive/id1482778676IOSYes-
https://apps.apple.com/fr/app/infomaniak-mail/id1622596573IOSYes-
https://github.com/Infomaniak/desktop-kDriveOTHERYes-
https://play.google.com/store/apps/details?id=com.infomaniak.driveANDROIDYes
https://play.google.com/store/apps/details?id=com.infomaniak.mail&hl=en_USANDROIDYes
infomaniak.eventsURLYes
invitation.infomaniak.comURLYes
ix2smbdyjt.infomaniak.siteURLYes
kmeet.infomaniak.comURLYes
kpaste.infomaniak.comURLYes
ksuite.infomaniak.comURLYes
l75pvbdyjo.infomaniak.siteURLYes
login.infomaniak.comURLYes
mail.infomaniak.comURLYes
manager.infomaniak.com/v3/*URLYes
player-radio.infomaniak.comURLYes
shop.infomaniak.comURLYes
sms.infomaniak.comURLYes
storage*.infomaniak.comURLYes
swiss-backup*.infomaniak.comURLYes
sync.infomaniak.comURLYes
vod.infomaniak.comURLYes
welcome.infomaniak.comURLYes
www.infomaniak.comURLYes
www.swisstransfer.comURLYes
Out-of-Scope Assets (14)
AssetCategoryBounty
Assets not listed in the in scope section are to be considered as out of the scope of this program and won't be eligible for rewardOTHERYes
Database service instances from customers, like *.dbaas.infomaniak.cloudOTHERYes
FTP credentials from our customers, like *.ftp.infomaniak.comOTHERYes
Jelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comOTHERYes
MySQL credentials from our customers, like *.myd.infomaniak.comOTHERYes
S3 credentials from our customers, like s3.pub*.infomaniak.cloudOTHERYes
This domain https://drive.infomaniak.com/app/office/:folder:/:file: is out of scope. This is only office application, an external app to open MS office documents.OTHERYes
User email verificationOTHERYes
VPS instances from our customers, like *.vps.infomaniak.comOTHERYes
We do not manage Open Stack dashboard which is therefore out of scopeOTHERYes
Websocket IPS-public credentials. Public identifiers that do not allow access to information outside the scope of the user's profile.OTHERYes
https://api.pub1.infomaniak.cloudOTHERYes
newsletter.infomaniak.comOTHERYes
ov-XX.infomaniak.ch and od-XX.infomaniak.ch sub domainsOTHERYes
Scope Changes (182)
Feb 25, 2026
ChangeAssetCategoryScopeTime
Addedhttps://api.pub1.infomaniak.cloudURLOut of Scope19:08
Addednewsletter.infomaniak.comURLOut of Scope19:08
Addedetickets.infomaniak.comURLIn Scope19:08
Addeddatabase service instances from customers, like *.dbaas.infomaniak.cloudWILDCARDOut of Scope19:08
Addedmanager.infomaniak.com/v3/*URLIn Scope19:08
Addedvod.infomaniak.comURLIn Scope19:08
Addedwelcome.infomaniak.comURLIn Scope19:08
Addedsms.infomaniak.comURLIn Scope19:08
Addedmysql credentials from our customers, like *.myd.infomaniak.comWILDCARDOut of Scope19:08
Addedwebsocket ips-public credentials. public identifiers that do not allow access to information outside the scope of the user's profileOTHEROut of Scope19:08
Addedapi.infomaniak.comURLIn Scope19:08
Addedcontacts.infomaniak.comURLIn Scope19:08
Addedeuria.infomaniak.comURLIn Scope19:08
Addedhttps://play.google.com/store/apps/details?id=com.infomaniak.driveANDROIDIn Scope19:08
Addedhttps://play.google.com/store/apps/details?id=com.infomaniak.mail&hl=en_USANDROIDIn Scope19:08
Added5k8vrbdyje.infomaniak.siteURLIn Scope19:08
Addedvps instances from our customers, like *.vps.infomaniak.comWILDCARDOut of Scope19:08
Addeds3 credentials from our customers, like s3.pub*.infomaniak.cloudWILDCARDOut of Scope19:08
Addedksuite.infomaniak.comURLIn Scope19:08
Addedcalendar.infomaniak.comURLIn Scope19:08
Addedplayer-radio.infomaniak.comURLIn Scope19:08
Addedwww.infomaniak.comURLIn Scope19:08
Addedchk.infomaniak.comURLIn Scope19:08
Addedkmeet.infomaniak.comURLIn Scope19:08
Addedkpaste.infomaniak.comURLIn Scope19:08
Addedhttps://apps.apple.com/fr/app/infomaniak-mail/id1622596573IOSIn Scope19:08
Added*.kdrive.infomaniak.comWILDCARDIn Scope19:08
Addedshop.infomaniak.comURLIn Scope19:08
Addedmail.infomaniak.comURLIn Scope19:08
Addedhttps://apps.apple.com/app/infomaniak-kdrive/id1482778676IOSIn Scope19:08
Addedfv3lfbdyjh.infomaniak.siteURLIn Scope19:08
Addedl75pvbdyjo.infomaniak.siteURLIn Scope19:08
Addedsync.infomaniak.comURLIn Scope19:08
Addedassets not listed in the in scope section are to be considered as out of the scope of this program and won't be eligible for rewardOTHEROut of Scope19:08
Addedftp credentials from our customers, like *.ftp.infomaniak.comWILDCARDOut of Scope19:08
Addeduser email verificationOTHEROut of Scope19:08
Addedlogin.infomaniak.comURLIn Scope19:08
Addedswiss-backup*.infomaniak.comWILDCARDIn Scope19:08
Added*.vod2.infomaniak.comWILDCARDIn Scope19:08
Addedwww.swisstransfer.comURLIn Scope19:08
Addedai-tools.infomaniak.comAIIn Scope19:08
Addedix2smbdyjt.infomaniak.siteURLIn Scope19:08
Addedinvitation.infomaniak.comURLIn Scope19:08
Addedwe do not manage open stack dashboard which is therefore out of scopeOTHEROut of Scope19:08
Addedstorage*.infomaniak.comWILDCARDIn Scope19:08
Addedhttps://github.com/Infomaniak/desktop-kDriveOTHERIn Scope19:08
Addedjelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comWILDCARDOut of Scope19:08
Addedjelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comWILDCARDOut of Scope19:08
Addedjelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comWILDCARDOut of Scope19:08
Addedadmin2.infomaniak.comURLIn Scope19:08
Added*.kchat.infomaniak.comWILDCARDIn Scope19:08
Addedinfomaniak.eventsURLIn Scope19:08
Addeddeveloper.infomaniak.comURLIn Scope19:08
Addedacademy.infomaniak.comURLIn Scope19:08
Addedov-xx.infomaniak.ch and od-xx.infomaniak.ch sub domainsURLOut of Scope19:08
Addedov-xx.infomaniak.ch and od-xx.infomaniak.ch sub domainsURLOut of Scope19:08
Addedthis domain https://drive.infomaniak.com/app/office/:folder:/:file: is out of scope. this is only office application, an external app to open ms office documentsURLOut of Scope19:08
Feb 22, 2026
ChangeAssetCategoryScopeTime
Addedplayer-radio.infomaniak.comURLIn Scope00:52
Addedfv3lfbdyjh.infomaniak.siteURLIn Scope00:52
Addedhttps://play.google.com/store/apps/details?id=com.infomaniak.mail&hl=en_USANDROIDIn Scope00:52
Addedacademy.infomaniak.comURLIn Scope00:52
Added*.kdrive.infomaniak.comWILDCARDIn Scope00:52
Addedlogin.infomaniak.comURLIn Scope00:52
Addedswiss-backup*.infomaniak.comWILDCARDIn Scope00:52
Added*.vod2.infomaniak.comWILDCARDIn Scope00:52
Addedkpaste.infomaniak.comURLIn Scope00:52
Addedstorage*.infomaniak.comWILDCARDIn Scope00:52
Addedinfomaniak.eventsURLIn Scope00:52
Addednewsletter.infomaniak.comURLOut of Scope00:52
Addedhttps://apps.apple.com/app/infomaniak-kdrive/id1482778676IOSIn Scope00:52
Addedksuite.infomaniak.comURLIn Scope00:52
Added*.kchat.infomaniak.comWILDCARDIn Scope00:52
Addedcalendar.infomaniak.comURLIn Scope00:52
Addedetickets.infomaniak.comURLIn Scope00:52
Addedwww.swisstransfer.comURLIn Scope00:52
Addedov-xx.infomaniak.ch and od-xx.infomaniak.ch sub domainsURLOut of Scope00:52
Addedov-xx.infomaniak.ch and od-xx.infomaniak.ch sub domainsURLOut of Scope00:52
Addedvps instances from our customers, like *.vps.infomaniak.comWILDCARDOut of Scope00:52
Addedmail.infomaniak.comURLIn Scope00:52
Addedvod.infomaniak.comURLIn Scope00:52
Addedchk.infomaniak.comURLIn Scope00:52
Addedai-tools.infomaniak.comAIIn Scope00:52
Addedix2smbdyjt.infomaniak.siteURLIn Scope00:52
Addedthis domain https://drive.infomaniak.com/app/office/:folder:/:file: is out of scope. this is only office application, an external app to open ms office documentsURLOut of Scope00:52
Addedmanager.infomaniak.com/v3/*URLIn Scope00:52
Addedcontacts.infomaniak.comURLIn Scope00:52
Addedkmeet.infomaniak.comURLIn Scope00:52
Addedhttps://github.com/Infomaniak/desktop-kDriveCODEIn Scope00:52
Addedsms.infomaniak.comURLIn Scope00:52
Addedhttps://api.pub1.infomaniak.cloudURLOut of Scope00:52
Addedftp credentials from our customers, like *.ftp.infomaniak.comWILDCARDOut of Scope00:52
Addedjelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comWILDCARDOut of Scope00:52
Addedjelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comWILDCARDOut of Scope00:52
Addedjelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comWILDCARDOut of Scope00:52
Addedhttps://play.google.com/store/apps/details?id=com.infomaniak.driveANDROIDIn Scope00:52
Addedadmin2.infomaniak.comURLIn Scope00:52
Addedshop.infomaniak.comURLIn Scope00:52
Addedapi.infomaniak.comURLIn Scope00:52
Addedwww.infomaniak.comURLIn Scope00:52
Addedsync.infomaniak.comURLIn Scope00:52
Addedhttps://apps.apple.com/fr/app/infomaniak-mail/id1622596573IOSIn Scope00:52
Added5k8vrbdyje.infomaniak.siteURLIn Scope00:52
Addedeuria.infomaniak.comURLIn Scope00:52
Addeddeveloper.infomaniak.comURLIn Scope00:52
Addedassets not listed in the in scope section are to be considered as out of the scope of this program and won't be eligible for rewardOTHEROut of Scope00:52
Addedwe do not manage open stack dashboard which is therefore out of scopeOTHEROut of Scope00:52
Addedmysql credentials from our customers, like *.myd.infomaniak.comWILDCARDOut of Scope00:52
Addeduser email verificationOTHEROut of Scope00:52
Addedwelcome.infomaniak.comURLIn Scope00:52
Addedl75pvbdyjo.infomaniak.siteURLIn Scope00:52
Addedinvitation.infomaniak.comURLIn Scope00:52
Addedwebsocket ips-public credentials. public identifiers that do not allow access to information outside the scope of the user's profileOTHEROut of Scope00:52
Addeds3 credentials from our customers, like s3.pub*.infomaniak.cloudWILDCARDOut of Scope00:52
Addeddatabase service instances from customers, like *.dbaas.infomaniak.cloudWILDCARDOut of Scope00:52
Feb 21, 2026
ChangeAssetCategoryScopeTime
Removed*.kdrive.infomaniak.comURLIn Scope21:40
Removedapi.infomaniak.comURLIn Scope21:40
Removedlogin.infomaniak.comURLIn Scope21:40
Removedmanager.infomaniak.com/v3/*URLIn Scope21:40
Removedadmin2.infomaniak.comURLIn Scope21:40
Removedshop.infomaniak.comURLIn Scope21:40
Removed*.kchat.infomaniak.comURLIn Scope21:40
Removedcalendar.infomaniak.comURLIn Scope21:40
Removedcontacts.infomaniak.comURLIn Scope21:40
Removedetickets.infomaniak.comURLIn Scope21:40
Removedmail.infomaniak.comURLIn Scope21:40
Removedswiss-backup*.infomaniak.comURLIn Scope21:40
Removedvod.infomaniak.comURLIn Scope21:40
Removed*.vod2.infomaniak.comURLIn Scope21:40
Removedplayer-radio.infomaniak.comURLIn Scope21:40
Removedwelcome.infomaniak.comURLIn Scope21:40
Removedwww.swisstransfer.comURLIn Scope21:40
Removedwww.infomaniak.comURLIn Scope21:40
Removedchk.infomaniak.comURLIn Scope21:40
Removedai-tools.infomaniak.comANDROIDIn Scope21:40
Removedkmeet.infomaniak.comURLIn Scope21:40
Removedkpaste.infomaniak.comURLIn Scope21:40
Removedsync.infomaniak.comURLIn Scope21:40
Removedstorage*.infomaniak.comURLIn Scope21:40
Removedeuria.infomaniak.comURLIn Scope21:40
Removedhttps://play.google.com/store/apps/details?id=com.infomaniak.driveANDROIDIn Scope21:40
Removedhttps://apps.apple.com/app/infomaniak-kdrive/id1482778676IOSIn Scope21:40
Removedhttps://github.com/Infomaniak/desktop-kDriveOTHERIn Scope21:40
Removedhttps://apps.apple.com/fr/app/infomaniak-mail/id1622596573IOSIn Scope21:40
Removedhttps://play.google.com/store/apps/details?id=com.infomaniak.mail&hl=en_USANDROIDIn Scope21:40
Removedix2smbdyjt.infomaniak.siteURLIn Scope21:40
Removed5k8vrbdyje.infomaniak.siteURLIn Scope21:40
Removedfv3lfbdyjh.infomaniak.siteURLIn Scope21:40
Removedl75pvbdyjo.infomaniak.siteURLIn Scope21:40
Removedinfomaniak.eventsURLIn Scope21:40
Removedsms.infomaniak.comURLIn Scope21:40
Removeddeveloper.infomaniak.comURLIn Scope21:40
Removedinvitation.infomaniak.comURLIn Scope21:40
Removedacademy.infomaniak.comURLIn Scope21:40
Removedassets not listed in the in scope section are to be considered as out of the scope of this program and won't be eligible for rewardOTHEROut of Scope21:40
Removedhttps://api.pub1.infomaniak.cloudOTHEROut of Scope21:40
Removedwe do not manage open stack dashboard which is therefore out of scopeOTHEROut of Scope21:40
Removednewsletter.infomaniak.comOTHEROut of Scope21:40
Removedov-xx.infomaniak.ch and od-xx.infomaniak.ch sub domainsOTHEROut of Scope21:40
Removedthis domain https://drive.infomaniak.com/app/office/:folder:/:file: is out of scope. this is only office application, an external app to open ms office documentsOTHEROut of Scope21:40
Removedftp credentials from our customers, like *.ftp.infomaniak.comOTHEROut of Scope21:40
Removedvps instances from our customers, like *.vps.infomaniak.comOTHEROut of Scope21:40
Removedmysql credentials from our customers, like *.myd.infomaniak.comOTHEROut of Scope21:40
Removedjelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comOTHEROut of Scope21:40
Removeduser email verificationOTHEROut of Scope21:40
Removedwebsocket ips-public credentials. public identifiers that do not allow access to information outside the scope of the user's profileOTHEROut of Scope21:40
Removeds3 credentials from our customers, like s3.pub*.infomaniak.cloudOTHEROut of Scope21:40
Removeddatabase service instances from customers, like *.dbaas.infomaniak.cloudOTHEROut of Scope21:40
Removedksuite.infomaniak.comURLIn Scope21:40
Addedhttps://api.pub1.infomaniak.cloudOTHEROut of Scope00:33
Addedwe do not manage open stack dashboard which is therefore out of scopeOTHEROut of Scope00:33
Addednewsletter.infomaniak.comOTHEROut of Scope00:33
Addedov-xx.infomaniak.ch and od-xx.infomaniak.ch sub domainsOTHEROut of Scope00:33
Addedthis domain https://drive.infomaniak.com/app/office/:folder:/:file: is out of scope. this is only office application, an external app to open ms office documentsOTHEROut of Scope00:33
Addedftp credentials from our customers, like *.ftp.infomaniak.comOTHEROut of Scope00:33
Addedassets not listed in the in scope section are to be considered as out of the scope of this program and won't be eligible for rewardOTHEROut of Scope00:33
Addedmysql credentials from our customers, like *.myd.infomaniak.comOTHEROut of Scope00:33
Addedjelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comOTHEROut of Scope00:33
Addeduser email verificationOTHEROut of Scope00:33
Addedwebsocket ips-public credentials. public identifiers that do not allow access to information outside the scope of the user's profileOTHEROut of Scope00:33
Addeds3 credentials from our customers, like s3.pub*.infomaniak.cloudOTHEROut of Scope00:33
Addeddatabase service instances from customers, like *.dbaas.infomaniak.cloudOTHEROut of Scope00:33
Addedvps instances from our customers, like *.vps.infomaniak.comOTHEROut of Scope00:33