
SEGA
External Program
Submit bugs directly to this organization
SEGA Europe Limited (“SEGA”) aims to provide safe and secure products and services to our gaming community. We value the role that the security community play and appreciate the importance of providing quick and effective means for you to contact us regarding potential vulnerabilities relevant to our customers’ privacy or the confidentiality, integrity or availability of our systems.
SEGA will use reasonable effort to meet the following SLAs for hackers participating in our Responsible Disclosure Programme:
| Type of Response | SLA in business days |
|---|---|
| First Response | 2 days |
| Time to Triage | 2 days |
| Time to Resolution | depends on severity and complexity |
We’ll try to keep you informed about our progress throughout the process.
You have been invited to participate in this Responsible Disclosure Programme (the “Programme”) for the sole purpose of identifying bugs and security vulnerabilities within our applications, websites, network and information technology services, processes and procedures (the “SEGA Systems”).
Before participating in this Programme, please read the following guidelines. By participating in the Programme, you may gain access to certain proprietary and confidential information (the “Confidential Information”) on the SEGA Systems. The Confidential Information should be held by you in the strictest confidence and you agree not to use, reproduce, or redistribute any of the SEGA Confidential Information except as expressly permitted in the Disclosure Policy. SEGA shall not be liable to you in any way for any loss or damage of any kind resulting from your access to the Confidential Information and/or participation in the security vulnerabilities programme.
If you do not agree with SEGA’s Responsible Disclosure Policy and the Programme Rules, please do not participate in our Responsible Disclosure Programme.
In addition to the Disclosure Policy, you shall comply with HackerOne's disclosure guidelines (https://www.hackerone.com/disclosure-guidelines).
At all times, you should act responsibly and in the best interests of SEGA and our customers, and in accordance with the following: • Do act in good faith • Do not break the law • Do not perform high volume scans that may interrupt services. • Do not use social engineering techniques against our customers or staff • Do not put SEGA, or our customer data or the SEGA Systems at risk • Do provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue may not be marked as triaged • Do provide a description of your assessment of the extent and impact of the vulnerability • Do provide your contact details so that we can follow up with you • Do provide a detailed and complete submission (masking or encrypting if necessary) • Do reference existing vulnerability information where relevant • Do ensure that you comply with the HackerOne disclosure guidelines • Do submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact. When duplicates occur, we only triage the first report that was received (provided that it can be fully reproduced). Multiple vulnerabilities caused by one underlying issue will be treated as one valid report • Do not use social engineering techniques (e.g., phishing, vishing, smishing). SEGA act decisively on attacks and extortion attempts, and we will report our concerns to the police where we believe such an attack or extortion attempt has been made • Do make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of the service. • Do ensure that you only interact with accounts you own or with the explicit permission of the account holder
Please note that SEGA does not respond to generic communications which are unrelated, vague, or with no direct evidence of a vulnerability relating to the SEGA Systems. Thank you for helping keep SEGA and our users safe!