
Worklytics
External Program
Submit bugs directly to this organization
No technology is perfect, and Worklytics believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. If you believe you've found a security issue in our product or service, we encourage you to notify us. We welcome working with you to resolve the issue promptly.
Keep in mind Hackerone's definition of Vulnerability. For the purposes of this program "design flaws" / "failures to adhere to security best practices" will generally be resolved as an informative report rather than a confirmed vulnerability.
Reports should have either 1) clear, concise reproducible steps, or 2) a working proof-of-concept (POC) - or they may be marked as "Needs More Info" until more detail is provided. If we mark a report as "Needs More Info" and do not receive a response within 7 days, we may close it as "Invalid/Not Applicable".
While researching, we'd like to ask you to refrain from:
Scope exclusions:
~all is the recommended practice by major providers like SendGrid, even if some scanners suggest you should use -all.worklytics.co, supports various weak TLS ciphersuites. We accept the risk this poses, given that this site does not serve non-public information and its use-case (marketing) justifies providing an experience that maximizes compatibility across browsers. Please focus TLS/ciphersuite reports on app.worklytics.co/intl.worklytics.co/app-eu.worklytics.co, which are domains that we use to serve customer data.[email protected]https://target.worklytics.co/{userName}.html)The following issues have been repeatedly reported as vulnerabilities, but we (and many others) don't consider them to be:
Any activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Thank you for helping keep Worklytics and our users safe!