Synack Vulnerability Disclosure Program | Synack

Synack Vulnerability Disclosure

Protect Synack by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.

Overview

This Responsible Disclosure Program (the “Program”) page is for security researchers interested in reporting application security vulnerabilities. This is intended for application security vulnerabilities only.

Vulnerabilities submitted to the Program through the form provided will be reviewed by Synack, Inc. (“Synack”). Submissions will be reviewed to confirm they are within the Program scope and a valid security issue. If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability. The submission review and validation process is managed exclusively by Synack through their platform, and you must follow the Guidelines, Rules of Engagement, and Scope set forth below to participate. All submissions and queries regarding the Program should be submitted through the Submission Form.

Guidelines

In submitting a request, you agree to:

The following web applications are in scope: *.synack.com

Rules of Engagement

Out of Scope – Low Impact Vulnerabilities

The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:

Additional specific vulnerability types considered out of scope due to low impact:

Terms of Use

The following terms apply when you view or use the Responsible Disclosure Program hosted by Synack, Inc. (“Synack”, “we”, “our”, “us”) on Synack’s websites.

Privacy Policy

We respect the privacy of our Site visitors. Please refer to our Privacy Policy which explains how we collect, use, and disclose information that pertains to your privacy.

Eligibility Requirements

You agree that you will not under any circumstances:

Suggestions and Feedback

We welcome your feedback and inquiries. If you have any comments or questions, please contact us by sending an email to support@synack.com.

Last updated

January 8, 2025

Company Information

Company Name: Synack
Website: https://www.synack.com/
About: Synack’s PTaaS platform helps you manage your attack surface by discovering new assets, pentesting for critical vulnerabilities and gaining visibility into the root causes of security risks.