# Synack Vulnerability Disclosure

Protect Synack by reporting security vulnerabilities through our Vulnerability Disclosure Program (VDP). Submit findings securely and support a transparent, proactive security process.

## Overview

This Responsible Disclosure Program (the “Program”) page is for security researchers interested in reporting application security vulnerabilities. This is intended for application security vulnerabilities only.

Vulnerabilities submitted to the Program through the form provided will be reviewed by Synack, Inc. (“Synack”). Submissions will be reviewed to confirm they are within the Program scope and a valid security issue. If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability. The submission review and validation process is managed exclusively by Synack through their platform, and you must follow the Guidelines, Rules of Engagement, and Scope set forth below to participate. All submissions and queries regarding the Program should be submitted through the Submission Form.

## Guidelines

In submitting a request, you agree to:  
- Accept and adhere to the Terms of Use.  
- Work directly with Synack on vulnerability submissions.  
- Provide a detailed description of a proof of concept to detail the reproduction of vulnerabilities.  
- Adhere to these Guidelines and the Rules of Engagement and Scope, and do not engage in disruptive testing like DoS or any action that could impact the confidentiality, integrity, or availability of information and systems.  
- Do not engage in social engineering or phishing of customers or employees.  
- Do not request compensation for time and materials or vulnerabilities discovered.

The following web applications are in scope: *.synack.com

## Rules of Engagement

- No Denial of Service testing  
- No Physical or Social Engineering  
- No testing of Third-party Services  
- No uploading of any vulnerability or client-related content to third-party utilities (e.g. Github, DropBox, YouTube)  
- All attack payload data must use professional language  
- If able to gain access to a system, accounts, users, or user data, stop at the point of recognition and report. Do not dive deeper to determine how much more is accessible.

## Out of Scope – Low Impact Vulnerabilities

The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:

- Google Maps API Keys  
- Account/e-mail enumeration using brute-force attacks  
  - Valid user account/email enumeration not requiring brute-force will be considered  
- Any low impact issues related to session management  
- Bypassing content restrictions in uploading a file without proving the file was received  
- Clickjacking/UI redressing  
- Client-side application/browser autocomplete or saved password/credentials  
- Descriptive or verbose error pages without proof of exploitability or obtaining sensitive information  
- Directory structure enumeration (unless the fact reveals exceptionally useful information)  
- Incomplete or missing SPF/DMARC/DKIM records  
- Issues related to password/credential strength, length, lockouts, or lack of brute-force/rate-limiting protections  
- Lack of SSL or Mixed content  
- Low impact Information disclosures (including Software version disclosure)

## Additional specific vulnerability types considered out of scope due to low impact:

- IIS Tilde File and Directory Disclosure  
- SSH Username Enumeration  
- WordPress Username Enumeration  
- SSL Weak Ciphers/ POODLE / Heartbleed  
- CSV Injection  
- PHP Info  
- Server-Status if it does not reveal sensitive information  
- Snoop Info Disclosures

## Terms of Use

The following terms apply when you view or use the Responsible Disclosure Program hosted by Synack, Inc. (“Synack”, “we”, “our”, “us”) on Synack’s websites.

## Privacy Policy

We respect the privacy of our Site visitors. Please refer to our Privacy Policy which explains how we collect, use, and disclose information that pertains to your privacy.

## Eligibility Requirements

You agree that you will not under any circumstances:

- Cause harm to us, our customers or others;
- Be a resident of, or make your Submission from, a country or region against which the United States has issued export sanctions or other trade restrictions;
- Be listed on the U.S. Department of the Treasury’s Specially Designated Nationals List;
- Be in violation of any national, state, or local law or regulation;
- Compromise our privacy or safety or the privacy or safety of our customers;
- Store, share, compromise or destroy our or our customers’ data; or
- Be less than 14 years of age. If you are at least 14 years old, but are considered a minor in your place of residence, you must get your parent’s or legal guardian’s permission prior to participating in the program.

## Suggestions and Feedback

We welcome your feedback and inquiries. If you have any comments or questions, please contact us by sending an email to support@synack.com.

## Last updated

January 8, 2025

## Company Information
**Company Name:** Synack  
**Website:** [https://www.synack.com/](/content/site-root.html)  
**About:** Synack’s PTaaS platform helps you manage your attack surface by discovering new assets, pentesting for critical vulnerabilities and gaining visibility into the root causes of security risks.
