kiteworks-public-bug-bounty-program-1
12
In Scope
1
Out of Scope
In-Scope Assets (12)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| API Playground | URL | Yes | - | |
| Crown Jewel Heist | CHALLENGE | Yes | - | |
| Email Protection Gateway (EPG) | URL | Yes | - | |
| Kiteworks Android App | ANDROID | Yes | - | |
| Kiteworks Core | URL | Yes | - | |
| Kiteworks Desktop Client 2.0 | OTHER | Yes | - | |
| Kiteworks for Desktop | OTHER | Yes | - | |
| Kiteworks for Office Desktop | OTHER | Yes | - | |
| Kiteworks for Outlook Desktop | OTHER | Yes | - | |
| Kiteworks iOS App | IOS | Yes | - | |
| Managed File Transfer (MFT) | URL | Yes | - | |
| Secure Data Forms (SDF, aka Advanced Forms) | URL | Yes | - |
Out-of-Scope Assets (1)
| Asset | Category | Bounty | |
|---|---|---|---|
| Testing is only authorized on the targets listed as in scope. Any domain/property of Kiteworks not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Kiteworks, you can report it here. However, be aware that it is ineligible for rewards or points-based compensation. | OTHER | Yes |
Scope Changes (13)
Sep 10, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | crown jewel heist | CHALLENGE | In Scope | 12:47 |
| Added | kiteworks core | URL | In Scope | 12:47 |
| Added | email protection gateway (epg) | URL | In Scope | 12:47 |
| Added | managed file transfer (mft) | URL | In Scope | 12:47 |
| Added | secure data forms (sdf, aka advanced forms) | URL | In Scope | 12:47 |
| Added | api playground | URL | In Scope | 12:47 |
| Added | kiteworks android app | ANDROID | In Scope | 12:47 |
| Added | kiteworks ios app | IOS | In Scope | 12:47 |
| Added | kiteworks for desktop | OTHER | In Scope | 12:47 |
| Added | kiteworks desktop client 2.0 | OTHER | In Scope | 12:47 |
| Added | kiteworks for outlook desktop | OTHER | In Scope | 12:47 |
| Added | kiteworks for office desktop | OTHER | In Scope | 12:47 |
| Added | testing is only authorized on the targets listed as in scope. any domain/property of kiteworks not listed in the targets section is out of scope. this includes any/all subdomains not listed above. if you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to kiteworks, you can report it here. however, be aware that it is ineligible for rewards or points-based compensation | OTHER | Out of Scope | 12:47 |