infomaniak-bug-bounty-program

40
In Scope
14
Out of Scope

In-Scope Assets (40)

AssetCategoryQuick Links
*.kchat.infomaniak.comURL
*.kdrive.infomaniak.comURL
*.vod2.infomaniak.comURL
5k8vrbdyje.infomaniak.siteURL
academy.infomaniak.comURL
admin2.infomaniak.comURL
ai-tools.infomaniak.comANDROID
api.infomaniak.comURL
calendar.infomaniak.comURL
chk.infomaniak.comURL
contacts.infomaniak.comURL
developer.infomaniak.comURL
etickets.infomaniak.comURL
euria.infomaniak.comURL
fv3lfbdyjh.infomaniak.siteURL
https://apps.apple.com/app/infomaniak-kdrive/id1482778676IOS-
https://apps.apple.com/fr/app/infomaniak-mail/id1622596573IOS-
https://github.com/Infomaniak/desktop-kDriveOTHER-
https://play.google.com/store/apps/details?id=com.infomaniak.driveANDROID
https://play.google.com/store/apps/details?id=com.infomaniak.mail&hl=en_USANDROID
infomaniak.eventsURL
invitation.infomaniak.comURL
ix2smbdyjt.infomaniak.siteURL
kmeet.infomaniak.comURL
kpaste.infomaniak.comURL
ksuite.infomaniak.comURL
l75pvbdyjo.infomaniak.siteURL
login.infomaniak.comURL
mail.infomaniak.comURL
manager.infomaniak.com/v3/*URL
player-radio.infomaniak.comURL
shop.infomaniak.comURL
sms.infomaniak.comURL
storage*.infomaniak.comURL
swiss-backup*.infomaniak.comURL
sync.infomaniak.comURL
vod.infomaniak.comURL
welcome.infomaniak.comURL
www.infomaniak.comURL
www.swisstransfer.comURL
Out-of-Scope Assets (14)
AssetCategory
Assets not listed in the in scope section are to be considered as out of the scope of this program and won't be eligible for rewardOTHER
Database service instances from customers, like *.dbaas.infomaniak.cloudOTHER
FTP credentials from our customers, like *.ftp.infomaniak.comOTHER
Jelastic subdomains : *.jcloud.ik-server.com, *.jpc.infomaniak.com, *.jpe.infomaniak.comOTHER
MySQL credentials from our customers, like *.myd.infomaniak.comOTHER
S3 credentials from our customers, like s3.pub*.infomaniak.cloudOTHER
This domain https://drive.infomaniak.com/app/office/:folder:/:file: is out of scope. This is only office application, an external app to open MS office documents.OTHER
User email verificationOTHER
VPS instances from our customers, like *.vps.infomaniak.comOTHER
We do not manage Open Stack dashboard which is therefore out of scopeOTHER
Websocket IPS-public credentials. Public identifiers that do not allow access to information outside the scope of the user's profile.OTHER
https://api.pub1.infomaniak.cloudOTHER
newsletter.infomaniak.comOTHER
ov-XX.infomaniak.ch and od-XX.infomaniak.ch sub domainsOTHER