
Pogo
External Program
Submit bugs directly to this organization
#Brand Promise
Pogo looks forward to working with the security community to find vulnerabilities in order to keep our businesses and customers safe.
#Rewards
#Safe Harbor
Any activities conducted in a manner consistent with this policy will be considered authorized conduct, and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will make it known that your actions were conducted in compliance with this policy. Pogo reserves all legal rights in the event of noncompliance with this policy.
#Program Eligibility
#Program Rules
Do
Do NOT:
#Disclosure Policy
You may not discuss this program or any vulnerabilities (even invalid and resolved ones) outside of the program without express consent from the organization. If you are interested in sharing any information about your testing methodology related to a Pogo report, you must request permission on your report and you must receive written approval from a Pogo team member.
#Legal
Pogo reserves the right to modify the terms and conditions of this program, and your participation in the Program constitutes acceptance of all terms. Please check this site regularly as we routinely update our program terms and eligibility, which are effective upon posting. You can subscribe to receive email notifications when this policy is updated.
#Scope exclusions
#F.A.Q.
Can I get Pogo swag?
Pogo does not currently offer swag
Can Pogo provide me with a pre-configured test account?
This program does not provide credentials or any special access
[I submitted a report. Now what? I have questions. Please email [email protected]
What causes a report to be closed as Informative, Duplicate, N/A, or Spam?
What is an example of an accepted vulnerability?
Valid and accepted vulnerabilities would be the type of report that identifies a unique security impact on this program’s specific scope. The report must also meet any submission criteria outlined in the policy, such as test plan instructions and a working proof of concept.