Scope Updates

Recent changes to bug bounty program scopes.

ChangeAssetCategoryScopeProgramPlatformTime
Addedov-xx.infomaniak.ch and od-xx.infomaniak.ch sub domainsOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addednewsletter.infomaniak.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedwe do not manage open stack dashboard which is therefore out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedhttps://api.pub1.infomaniak.cloudOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedassets not listed in the in scope section are to be considered as out of the scope of this program and won't be eligible for rewardOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedall pdf documents published or served on castor.vinci.com are public, thank you for not reporting any bug linked to the accessibility of these documentsOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedonly exception: wishes.vinci.com (english version of voeux.vinci.com) is included in the scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added!! links pointing to other fqdns are always out of scope !!OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedanything that is not explicitely listed in scope sectionOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedplease note that www.lafabriquedelacite.com is out of scope from today 10/12/25 as the web site is going to be redevelopedOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedfinally, fraud related reports are out-of-scope if they do not exploit a security vulnerability. therefore, fraud activity enabled by bug or incomplete business rules enforcement are out-of-scope. however, a fraud activity enabled by a csrf exploit for example is validOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedhowever, though listed in the out-of-scope list, if you really feel that a bug will leave an impact on our platform, please come up with a convincing and working poc. if that convinces us to change our code, we will reward you with a bountyOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany website that is not listed explicitly in the scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedplease note that https://dev.blablacar.com is hosted by a third party and thus is out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedexperimental featuresOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany local implementation of the project/implementation belonging to third partiesOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany depreciated versions and other versions than the current stable/official version are considered out of scope except if specified otherwise in the program’s rulesOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany third parties’ or community’s assets that are not explicitly included (e.g. forks, libraries or packages)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany asset that is not explicitly included in our program's scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added- all other goto financial assets not listed above are to be considered as out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Added- any staging environment will be out of scope (staging domain could be indicated by words like test/integration/staging, etc)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedall other goto assets not listed above are to be considered as out of scopeOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedany staging environment will be out of scope (staging domain could be indicated by words like test/integration/staging, etc)OTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedcraft cms on www.siilo.comOTHEROut of ScopeYesWeHack2026-02-21 00:33
Addedvettore.it (and any related vettore assets)OTHEROut of ScopeYesWeHack2026-02-21 00:33