feat: add bug bounty program (#1433)

This commit is contained in:
Tim Eggert
2025-02-07 10:02:46 +01:00
committed by GitHub
parent f5b6a5811e
commit 840f832581
5 changed files with 155 additions and 0 deletions
+4
View File
@@ -103,6 +103,10 @@ menuItems:
name: Startup Program
icon: qdrant-for-startups.svg
url: /qdrant-for-startups/
- id: subMenu-3-5
name: Bug Bounty Program
icon: bug-bounty-program.svg
url: /security/bug-bounty-program/
- id: menu-4
name: Company
subMenuItems:
@@ -0,0 +1,9 @@
---
title: Security
sitemapExclude: True
_build:
render: never
cascade:
- build:
render: always
---
@@ -0,0 +1,57 @@
---
title: Bug Bounty Program
---
# Bug Bounty Program Overview
We prioritize user trust and adhere to the highest privacy and security standards. This is why we actively invite security experts to identify vulnerabilities and commit to collaborating with them to resolve issues swiftly and effectively.
Qdrant values the security research community and supports the responsible disclosure of vulnerabilities in our products and services. Through our bug bounty program, we reward researchers who help enhance the security of our platform.
## Responsible Disclosure Program Rules
- Include detailed, reproducible steps in your reports. We will not reward issues you cannot reproduce.
- Submit one vulnerability per report unless you need to chain multiple vulnerabilities to demonstrate impact.
- In cases of duplicate reports, we will reward only the first reproducible report.
- We will consider vulnerabilities stemming from the same root cause as a single issue and award only one bounty.
- We strictly prohibit social engineering attacks (e.g., phishing, vishing, smishing).
- Interact only with accounts you own or have explicit permission to access. Do not test using Qdrant employee accounts or internal tools.
- Before you run automated scanners, please check with us first.
### In Scope
We cover vulnerabilities in the following areas:
- *.cloud.qdrant.io Qdrant Cloud Application
- [qdrant.tech](http://qdrant.tech/) Website
### Out of Scope
We always exclude the following areas:
- Third-party applications or websites
- Staging or test environments
- Social engineering attacks
- DoS/DDoS attacks
- User/email enumeration
- Brute-force attacks
- Physical security issues
- Reports from automated tools or scanners
- Generic information disclosure, such as the `Server` or `X-Powered-By` headers
- Email security: DMARC, DKIM, SPF
- Spamming that rate limiting techniques can prevent
## Severity Levels and Rewards
- We assess reported bugs based on their risk and other relevant factors; our response may take some time.
- We tend to award higher rewards for submissions that include detailed remediation steps or recommendations.
- We determine bounty amounts based on multiple factors, including the vulnerability’s impact, the ease of exploitation, and the quality of the report. Please note that we may not award a bounty for very low-risk issues.
- We use the CVSS v4 framework to evaluate the criticality of issues and ensure a consistent risk assessment.
- We aim to reward similar vulnerabilities with comparable compensation; however, we also consider factors such as the time and effort required to discover the issue. Keep in mind that we may not match previous compensations for future reports.
## Disclosure Policy
Contact us at [security@qdrant.com](mailto:security@qdrant.com) to report vulnerabilities. Our security team will provide an initial response within 5 business days and triage the issue within 5-7 business days. We vary fix implementation timelines based on severity, and we process bounty payments after verifying the fix.
Follow these guidelines when disclosing vulnerabilities to us:
- Report any potential security vulnerabilities immediately upon discovery, as we commit to resolving issues swiftly.
- Maintain strict confidentiality regarding discovered vulnerabilities. Obtain explicit authorization from the Qdrant security team before publicly disclosing any vulnerabilities.
- Exercise caution to prevent data loss, privacy breaches, or service disruptions while conducting security research.
- Limit testing to your own accounts or those for which you have received explicit permission. Report any accidental access to unauthorized data immediately.
- **Safe Harbor:** We support ethical security research and promise not to initiate legal action against researchers who report vulnerabilities in good faith and comply with this disclosure policy. Ensure that your testing remains non-disruptive and respects the outlined guidelines so you qualify for Safe Harbor protections.
### Contact
For questions about the program or to report security issues, contact:
- Email: [security@qdrant.com](mailto:security@qdrant.com)
- PGP Key Fingerprint: [07E3 6646 E0D0 A3BF 0AFC B302 26C5 016B 97EB 804B](/misc/qdrant-security-public-key.asc)
@@ -0,0 +1,10 @@
<svg width="17" height="16" viewBox="0 0 17 16" fill="none" xmlns="http://www.w3.org/2000/svg">
<g clip-path="url(#clip0_7459_6923)">
<path d="M8.83333 4.66634V14.9997M8.83333 4.66634C7.5 4.66634 6.16667 3.66634 6.16667 3.66634C6.36667 2.33301 7.5 1.33301 8.83333 1.33301C10.1667 1.33301 11.3 2.33301 11.5 3.66634C11.5 3.66634 10.1667 4.66634 8.83333 4.66634ZM8.83333 14.9997C11.7667 14.9997 14.1667 12.2619 14.1667 8.95101C14.1667 6.65885 13.1 4.68507 11.4333 3.66634M8.83333 14.9997C5.9 14.9997 3.5 12.2619 3.5 8.95101C3.5 6.65885 4.63333 4.68507 6.23333 3.66634M3.5 8.99967H1.5M16.1667 8.99967H14.1667M3.5 3.66634L4.83333 4.99967L4.5 4.66634M14.1667 14.333L12.8333 12.9997L13.0715 13.2377M3.5 14.333L4.83333 12.9997L4.74201 13.091M14.1667 3.66634L12.8333 4.99967L13.0431 4.78995" stroke="#DC244C" stroke-linecap="round" stroke-linejoin="round"/>
</g>
<defs>
<clipPath id="clip0_7459_6923">
<rect width="16" height="16" fill="white" transform="translate(0.5)"/>
</clipPath>
</defs>
</svg>

After

Width:  |  Height:  |  Size: 991 B

@@ -0,0 +1,75 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBGeYlmABEADcLHOGaeAunXYRv49saZ+khtCM8PWD6g4qenqEcmHXqt3BQecU
w630JMf5n5v+G95QLc8foUnS+sp+/O4FxoBhaEC2A5SIsJdp0bULDA2OUaoXU31m
nqpg5lf5S2p3gtO2qLmMHeHMNzz8rRY3r0Ds8cpm74FPjKLHxPOzLuot3WAMAHYp
kSmgCHKpSVj0b1qoWj7jprEvvyAya4LHPmNlfkTbRYX2lOUYLlUei3X5eHhmdWGe
rNzid59qsNuxkUo5zp0mNrnKU1FXlYyOTTTc9ey0aHVa4nvIyMpplFQbkeVChfup
QG97Pc37+jTaM+NBXylGavn0Jk15vj1WKQsuz6OaxdOIAsQ+7DLV2T1KsF7yMA2r
giRwtmB1tAK0abcdagLQQU0HbHSYOvCKHzjTWS6n776Rk0ndY+wrVCD9NsrO3KbE
rM/rgHtw3TWRzRU8UOCCRujSqTzvhAv3pePsU7luddVQ/qKC+6ptDqTA5Hc7xLua
XyrEooRPxdsoplI0fy9Ldin53nXjB+U8pj2hw4/9kmLoN+S3qI8S2+v4OYxe7792
uNlKB+A/gczTjBlAl7xQM2modO5HWuuoGUCreeSV4Zao7Rf7hGdX8MMQZP4apZ6a
nDCZlC47gMkoDS+Qsv5SxxS8PxRW2iw8bWTaBsa62J/i+rETcL0x9G2G7wARAQAB
tCpRZHJhbnQgU2VjdXJpdHkgVGVhbSA8c2VjdXJpdHlAcWRyYW50LmNvbT6JAlQE
EwEIAD4WIQQH42ZG4NCjvwr8swImxQFrl+uASwUCZ5iWYAIbAwUJB4YfGQULCQgH
AgYVCgkICwIEFgIDAQIeAQIXgAAKCRAmxQFrl+uAS4XdEACooZX9N6qFX4hv3D11
fKP+PyZ9VdJs2dKqwK2GMnUxx0vaJaah0dvxuQxbtGY1ISUq0PlaWoE0LdqHXtxm
/XGlwqERoWN9CiHMfTFZPXeZVeN5gkBcM5r4849iH+0s8Nvb/9rUN9N6Lac51BYx
rxH+it4nlFQfeVdM3Pd4jO9rQE7ll1BYbibFZsqhgBzKONOuDny3lm0AhEZEh/Yx
OfADBhxkz9JW7j6ekZ8LobGSXGNyNFHcoWcazShfnfN4oRBGiMi6vccvLJmm+5kw
DerBw4sJzx2BvoxI/JVh1Gg2cSawqs+XXTg+uwQqLZnc2tT8Swab51raJtpt7TcM
wqBLKSdqa1fY85tg/apZJd9vfpYDGzUxtXvdYwg8z74hHgtarjww5ZevSKDI/qBL
GjdYzOyF9BcGK4KXhfzukgq777QZFOzKfacWKu5o017WdRojxhZFLJLtvewrMfTS
kRI/9lITCYl/iyBw5SxFWNIfn3ZDy7IWGCDw91ozR2XMLeaiP27SAXhTXClIwRUA
ZhBnTr0fiKehx1RIqr8EWgUOS68Bd5dqLPdFBj1ycIf7i6+m9UvZ2kkKoDr88rFo
OCTtj1seziPVz1nCVIlLJtTFFT7HMfu2WkAAZ8RhMZAd+dKozWkWBsmuLP+43MP6
E4ZAtwU8KeXLQ4KpSmaiALd4ULkCDQRnmJZgARAA2SZ8X+NvBkgPR7RyC2YUxgUo
vLPoz0MpY4gbx8X8ul+E52ZSJLm3Xc1eATKFPcmEkioWS0700VRHLZ2CLPrBWiTP
iwZoL4rYpGrkkSyr+A1HKV4QewBh7UEhCTut1iaxcd4n8W3OBYtRkidYiNcjnJWP
w95qRzbRy5/STm8pVdhOpgagIwVXydgHk5sGDO865ZTU6ej/HSGi1aslBjy2PtPi
RCDp6FbFAMGqTvTKPratGtJCOkyylJw8qwtagvxTnkjWSiDwQTTLFoMQstam5V3z
rHO/WmrZW3xCf9jHxWWU56kiR2huA5H0roZhPMY4gxya+PM7XVPEkrQOf3B4CHjg
vG1oSfgXYAdRn7GQlSh4K4srbMzws57AJ6OwBKhx4ghYDAl7V46tUvcH38p7NGgV
u+/JkwLP2kTSJ6SJekVBzrscGPymI0iMwsWCTv2BknN3m8PTrlgPBSvDK+Ay+ze2
u1X/uEHNugHur3IuoaI4pbicUnoJh4ThlEo4+/fDaQr1OVIR6+3AB/BJ0KXjO9oV
5LflPsjui4OI9iecJYGihXWDroFwUWzAVDxnVC7fZu+B9OscP79zvKKxg3QvxOdo
Z08K7GULpliOTOmm93aaZraSv86jUGbVaHlZxY/NPyN85WXJNkE8E8sXL64I2sYn
OftlbtS7fjUZi/50W5MAEQEAAYkCPAQYAQgAJhYhBAfjZkbg0KO/CvyzAibFAWuX
64BLBQJnmJZgAhsMBQkHhh8ZAAoJECbFAWuX64BLMtcP/0PMatMj3cr7GiXDMKOr
uVA5CQ0BbBX8YLrIZnwYA8B7948vsij/7w6UDacYxVYu10gXLl+xuINUUPRntHZW
hZUtV4gux21SrXmQBU//INyDJSZLIwrKylJwnpqoPdS8sVrxU3k41lBmJ+XjzQ6g
+iQ5jCtadcbmQty+yUq6qzXJw2NAMmeLaxyGJzB48F+K1SPbxNHJGOOYzBj6Abz+
MT6q0fO3Pu3nSVHrJHF93ea1JbkT+V3V8bJEN5nqkq0uTbBS0I1vWOYLzNrATqLS
0AY827oYfN4XQnlIS4l+2EJYwBmDiXUNbpb7Aoq6ySaUhbXOtbbzLuMhTTGzb6Vg
BDKyxV+fdmkCOC7UiSJnx184xgITuA1m4019q54Er6tjHqFJliNBYBkpXrTubtM+
2ljiDn5X3i8Gq/+1IXFq6+LJzdNDcPGOslm8vDm/IX8Zoj/HxLW7vmfUT+9PBqqQ
EGmNZ8mTJH2if/R+mZ3tuAHpa1FWKPdmgolaPN3JjwY3dwOkQGmBk9Kx2J+07fSj
P6row5ZVbQNdZtVUSwH20z35BpUE/XlHrtJ/wjCOQhIRdzxg0zZhwdjy85lednyF
GJIMoJ1nED42P8wru1iHvnsHjykYPESsf1zob8KAviY8FG2LDo+NrN1wbqEUX8mg
JPrQx6zbpJ0wbcBt398S/FYfuQINBGeYlqUBEADIgu0ateMD9AOByz2+8G2LHcdS
uwnMScz/14VQvIyAAteK4KHRTINy6IGtFG1UaNlMOR8Z+EsMTF9ueTLWY2L2a3bZ
ZGrKutanPUArkL5E1ywi4G1TKTtMJtYPkpvWs6u5pSrX0EVXJ85Px1GzZQi0hCyt
j6IIzyEOQjCA/9pvAjU5xsgOAuktZUk8kffsQX3OWFvmWNhcBMXQYH0sXUofho/R
sUD/QxwTvS0INR5S1NOGLu4gkOieMCeSpMp5ZPpdXiGCnFRBc4kdGDK6DjHVBhE/
d/bV8eHqL6azen6K6MGPZeQ6rppiYH2HUvOuVPvJde7EanVpMuMGnZEDtoYHFuFc
XFWfQor3tBSD991jfVmfOK7SzkFqD8W/Z24E8dUj6QEDa0Zipnxy/M2Z39eFgy1N
gKre2DRtmZXAVPhFdK6LANv4klYiV0l9fW90Fq8hQNVcgRSLWGEi2X9eskaDZlLS
VtJk8cw6W6edmyoVYnYI/ZNy65uLrCzOe5XGPdxz1viu22ZL7ypSnDQvRBk6abiO
18v/dhnLNrFv6bsA7YRMJZztg0VKO1afMtTHbrOU8ysv8Nyt1DJOB7Mv8PsBbQFr
erBEMWfdnbAkdR4Un6OgM7N72riNGl3qAWQwPQN3GSY7hBloBLpnRg+rVMV1Csef
Q6C9QNh9B27tzrMCBQARAQABiQI8BBgBCAAmFiEEB+NmRuDQo78K/LMCJsUBa5fr
gEsFAmeYlqUCGwwFCQeGH2sACgkQJsUBa5frgEuoCw/+IHl7HjjUrDQFvtwkYLlt
W+bFkPnnJzZC7pysyrZgJX0uPot748Tif8Dx6xesKpJo64iUZ7nuEpNe3QxpT9Ll
FldrLXzSUphjBUVyxvUzkGRutIP+Kmu2D619kIpDYm2Q7fRZh5IbK6GrZBmZNQye
0SMnpqucU6u114ahIyH/twvpZc7wxbpRbiuqRHUs3/EPoGxKNrrASy5PZt3a5V5r
dg2komrJ84YycgtnhQg4E3Z9cosEnvFMcTng32cvHWWug58cFk7EXQZsT/7yFcQB
ksw3eVkX1EXjpQluMwYI0N5wnATQzrpCiudHDb0Nxh4ivZiOm7I0uNRFy7+6JO0n
hPrZTZHGU/XbYYm1/IZ0sm0Re3QHE6j0DwZYJ/8uk7bR5ePI6FDI/WAXK/w4gg25
i7J3hDuk+I1Z7PKHlrQO2sVW/rsLoszYZgqa/m6PmVy/Bfv5dMbi8jrjQ69tYdFT
0tmDh2SAef7SaxgOYf0X2hZsQLFYaRWTjoSNyL34bjiTJoPwiTD0boqzQoytYa1z
KvaVjlPn8TozqmLr37mL92pc/tfT2DAy4Dmr9nEQBlqlQFwXaGa+Kg42CEudai9S
AbB/jF5WNxh0DZcNJtibPxPR9UOkS3HTqsvOhpn/K/FdYqnhHfrx/7MqlVvwAJJW
/faVtAZX94Poc1FZj6YbXZE=
=9HbW
-----END PGP PUBLIC KEY BLOCK-----