— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Faraday, Inc..
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 78,
"average_time_to_first_program_response": 8,
"average_time_to_report_resolved": 78,
"handle": "faraday_inc",
"id": 0,
"managed_program": true,
"name": "Faraday, Inc.",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 99,
"submission_state": "open",
"url": "https://hackerone.com/faraday_inc",
"website": "https://faraday.ai",
"targets": {
"in_scope": [
{
"asset_identifier": "BigQuery",
"asset_type": "OTHER",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Faraday-managed datasets. Unauthenticated or cross-account access to Faraday or other customers' data is in scope. Access to a project you were granted is not a finding.",
"integrity_requirement": "low",
"max_severity": "critical"
},
{
"asset_identifier": "api.faraday.ai",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "JWT is the user, not the account. Switching accounts changes what the JWT can do. API keys are shared by every member and appear in GraphQL, REST, and the UI; seeing your own key is intended. Cross-account requires curl from two unrelated users (different emails, never invited, not a parent/sub pair) with a fresh JWT taken after /v1/me or /v1/accounts/current shows the attacker. Connecting to a host you configured (Connections, SFTP, webhooks) is the product. SSRF is in scope only if the worker reaches Faraday-internal or other-customer space. Proof is reachability, not a pasted secret. Catalog attributes are public at https://faraday.ai/catalog",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "api.pro.faraday.ai",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Catalog histograms and Faraday-provided consumer attributes are public (https://faraday.ai/catalog). Cross-account requires two unrelated users and curl from both sides. Copy a fresh token after the session shows the attacker identity. A 200 on your own resource is not evidence. Admin vs member privilege gain is in scope.",
"integrity_requirement": "low",
"max_severity": "critical"
},
{
"asset_identifier": "api.row.pro",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Catalog histograms and Faraday-provided consumer attributes are public (https://faraday.ai/catalog). Cross-account requires two unrelated users and curl from both sides. Copy a fresh token after the session shows the attacker identity. A 200 on your own resource is not evidence. Admin vs member privilege gain is in scope.",
"integrity_requirement": "low",
"max_severity": "critical"
},
{
"asset_identifier": "app.faraday.ai",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Same auth model as api.faraday.ai. Frontend \"enabled\" flags and hidden consoles are intended; access control is at the API. Non-secret tokens in /api/environment.js and public third-party client tokens (PostHog, Knock, Algolia, Auth0 client id, Rollbar, Intercom) are out unless you use one to read or change another customer's data. Self-XSS is out. Stored XSS is in only if it runs for a victim who is not the attacker.",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "gs://faraday-secret",
"asset_type": "OTHER",
"availability_requirement": "none",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Unauthenticated or cross-account read/write of Faraday secrets. Listing or reading under a prefix you own is not a finding.",
"integrity_requirement": "low",
"max_severity": "critical"
},
{
"asset_identifier": "gs://fdy-production-sdk-uploads",
"asset_type": "OTHER",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Customer upload bucket. Unauthenticated or cross-account read/write is in scope. Listing is prefix-scoped to the caller account; seeing your own prefix is not a finding.",
"integrity_requirement": "low",
"max_severity": "critical"
},
{
"asset_identifier": "mcp.faraday.ai",
"asset_type": "URL",
"availability_requirement": "medium",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Unauthenticated tool execution or customer data without a valid Faraday API key is in scope. Listing tools is out. Running tools with a valid key is the product.",
"integrity_requirement": "medium",
"max_severity": "critical"
},
{
"asset_identifier": "pro.faraday.ai",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Catalog histograms and Faraday-provided consumer attributes are public (https://faraday.ai/catalog). Cross-account requires two unrelated users and curl from both sides. Copy a fresh token after the session shows the attacker identity. A 200 on your own resource is not evidence. Admin vs member privilege gain is in scope.",
"integrity_requirement": "low",
"max_severity": "critical"
},
{
"asset_identifier": "row.pro",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Catalog histograms and Faraday-provided consumer attributes are public (https://faraday.ai/catalog). Cross-account requires two unrelated users and curl from both sides. Copy a fresh token after the session shows the attacker identity. A 200 on your own resource is not evidence. Admin vs member privilege gain is in scope.",
"integrity_requirement": "low",
"max_severity": "critical"
},
{
"asset_identifier": "s3://faraday-secret",
"asset_type": "OTHER",
"availability_requirement": "none",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Unauthenticated or cross-account read/write of Faraday secrets. Listing or reading under a prefix you own is not a finding.",
"integrity_requirement": "none",
"max_severity": "critical"
},
{
"asset_identifier": "s3://faraday-uploads",
"asset_type": "OTHER",
"availability_requirement": "none",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "",
"integrity_requirement": "none",
"max_severity": "critical"
},
{
"asset_identifier": "vault2.faraday.ai",
"asset_type": "URL",
"availability_requirement": "high",
"confidentiality_requirement": "high",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Reachable from the public internet (no IP allowlist) is intended. Do not report that. Unauthenticated access to secrets is in scope. DoS, including resource exhaustion, is out.",
"integrity_requirement": "high",
"max_severity": "critical"
}
],
"out_of_scope": [
{
"asset_identifier": "Support Live Chat",
"asset_type": "OTHER",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Support Live Chat is provided by Hubspot. If you have any security issues to report, use https://hackerone.com/hubspot",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "faraday.ai",
"asset_type": "URL",
"availability_requirement": "low",
"confidentiality_requirement": "low",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Public marketing site. Not eligible. Do not report missing headers, cache issues, or open redirects. Do not book a demo while testing.",
"integrity_requirement": "low",
"max_severity": "none"
},
{
"asset_identifier": "faraday.atlassian.net",
"asset_type": "URL",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "",
"integrity_requirement": "none",
"max_severity": "none"
}
]
}
}BigQuery· criticalgs://faraday-secret· criticalgs://fdy-production-sdk-uploads· criticals3://faraday-secret· criticals3://faraday-uploads· criticalSupport Live Chat