— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for DigitalOcean.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"id": "dd9dba85-e047-42f3-b59e-9328c7d49672",
"name": "DigitalOcean",
"company_handle": "digitalocean",
"handle": "digitalocean",
"url": "https://www.intigriti.com/programs/digitalocean/digitalocean/detail",
"status": "open",
"confidentiality_level": "public",
"tacRequired": false,
"twoFactorRequired": false,
"min_bounty": {
"value": 50,
"currency": "USD"
},
"max_bounty": {
"value": 10000,
"currency": "USD"
},
"targets": {
"in_scope": [
{
"type": "wildcard",
"endpoint": "*.digitalocean.com",
"description": "Please review the __*.digitalocean.com Out of Scope Subdomains__ section below to ensure testing of only in-scope domain assets.",
"impact": "Tier 2"
},
{
"type": "iprange",
"endpoint": "169.254.169.254",
"description": "Metadata service available at http://169.254.169.254/ from Droplets",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "api.digitalocean.com",
"description": null,
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "cloud.digitalocean.com",
"description": "Findings against resources owned by your account should be filed underneath this asset.\n\n* While performing your research, please limit the scope of testing to only the accounts or resources that are owned by you.\n* If you discover a vulnerability that could allow you to bypass existing controls and gain access to other accounts, **please do not take any further action** against those accounts or data that are not owned by you.",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "amd.digitalocean.com",
"description": "This asset follows the same testing guidelines as `cloud.digitalocean.com`.\n\n* While performing your research, please limit the scope of testing to only the accounts or resources that are owned by you.\n* If you discover a vulnerability that could allow you to bypass existing controls and gain access to other accounts, **please do not take any further action** against those accounts or data that are not owned by you.\n\nNote that we consider `cloud.digitalocean.com` and `amd.digitalocean.com` as having functionally the same backend codebase.",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "inference.do-ai.run",
"description": "DigitalOcean Serverless Inference API",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "marketplace.digitalocean.com",
"description": "Note that marketplace 1-click apps and add-ons are maintained by our partnered vendors and are out of scope. \nPlease see the \"Out of Scope\" section below for more info.",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "www.digitalocean.com",
"description": null,
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "digitaloceanmirrors.com",
"description": null,
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "digitaloceanpartners.com",
"description": null,
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "digitaloceanstatus.com",
"description": null,
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "digitaloceantest.com",
"description": null,
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "do.co",
"description": "Company shortlink service",
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "hackathon-tracker.digitalocean.com",
"description": "API for hacktoberfest.com",
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "hacktoberfest.com",
"description": null,
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "paperspace.com",
"description": "We do not currently offer bounty rewards for findings related to the `paperspace.com` domain or associated sub-domains.",
"impact": "No Bounty"
},
{
"type": null,
"endpoint": "https://github.com/digitalocean/do-agent",
"description": "A daemon that helps collect system metrics from droplets",
"impact": "No Bounty"
},
{
"type": null,
"endpoint": "https://github.com/digitalocean/droplet-agent",
"description": "A daemon that enables web console access on droplets",
"impact": "No Bounty"
},
{
"type": null,
"endpoint": "https://github.com/digitalocean/doctl",
"description": "The official command line interface for the DigitalOcean API",
"impact": "No Bounty"
},
{
"type": null,
"endpoint": "https://github.com/digitalocean/terraform-provider-digitalocean",
"description": "DigitalOcean's official Terraform provider",
"impact": "No Bounty"
}
],
"out_of_scope": [
{
"type": "wildcard",
"endpoint": "*.snapshooter.com",
"description": "SnapShooter is a cloud backup and recovery solution.",
"impact": "Out of scope"
},
{
"type": null,
"endpoint": "https://github.com/digitalocean/action-doctl",
"description": "GitHub Actions for DigitalOcean - doctl",
"impact": "Out of scope"
},
{
"type": null,
"endpoint": "https://github.com/digitalocean/godo",
"description": "DigitalOcean's Go API client",
"impact": "Out of scope"
},
{
"type": null,
"endpoint": "https://github.com/digitalocean/pydo",
"description": "DigitalOcean's Python API client",
"impact": "Out of scope"
},
{
"type": null,
"endpoint": "https://github.com/digitalocean/go-nbd",
"description": "Golang-only network block device client",
"impact": "Out of scope"
},
{
"type": null,
"endpoint": "https://github.com/digitalocean/do-markdownit",
"description": "Markdown plugin run against all user-submitted content on https://digitalocean.com/community",
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "anchor.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "brand.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "cloudsupport.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "deploy.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "email.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "events.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "go.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "groove.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "helpdesk.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "ideas.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "investor.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "investors.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "ir.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "mirrors.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "pilot.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "rewards.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "segment.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "status.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "tracking.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "url",
"endpoint": "waves.digitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "wildcard",
"endpoint": "*.db.ondigitalocean.com",
"description": "Customers' resources are hosted underneath this domain, so the entire domain should be considered out-of-scope.\n\nAny database created inside your own account on this domain are considered in-scope. Use the `cloud.digitalocean.com` asset in that case.\n\nFindings in Standard Edition PostgreSQL, Standard Edition MySQL, Valkey, Kafka, and OpenSearch should be submitted to [our partner, Aiven](https://bugcrowd.com/engagements/aiven-mbb-og).",
"impact": "Out of scope"
},
{
"type": "wildcard",
"endpoint": "*.db1.ondigitalocean.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "wildcard",
"endpoint": "*.digitaloceanspaces.com",
"description": "Customers' resources are hosted underneath this domain, so the entire domain should be considered out-of-scope.\n\nAny Spaces buckets created inside your own account on this domain are considered in-scope. Use the `cloud.digitalocean.com` asset in that case.",
"impact": "Out of scope"
},
{
"type": "wildcard",
"endpoint": "*.doserverless.co",
"description": "Customers' resources are hosted underneath this domain, so the entire domain should be considered out-of-scope.\n\nAny Functions created inside your own account on this domain are considered in-scope. Use the `cloud.digitalocean.com` asset in that case.",
"impact": "Out of scope"
},
{
"type": "wildcard",
"endpoint": "*.k8s.ondigitalocean.com",
"description": "Customers' resources are hosted underneath this domain, so the entire domain should be considered out-of-scope.\n\nAny Kubernetes clusters created inside your own account on this domain are considered in-scope. Use the `cloud.digitalocean.com` asset in that case.",
"impact": "Out of scope"
},
{
"type": "wildcard",
"endpoint": "*.ondigitalocean.app",
"description": "Customers' resources are hosted underneath this domain, so the entire domain should be considered out-of-scope.\n\nAny Apps created inside your own account on this domain are considered in-scope. Use the `cloud.digitalocean.com` asset in that case.",
"impact": "Out of scope"
},
{
"type": "wildcard",
"endpoint": "registry.digitalocean.com/*",
"description": "Customers' resources are hosted underneath this domain, so the entire domain should be considered out-of-scope.\n\nAny container registries created inside your own account on this domain are considered in-scope. Use the `cloud.digitalocean.com` asset in that case.",
"impact": "Out of scope"
},
{
"type": "other",
"endpoint": "Assets created by other DigitalOcean customers",
"description": "**Any asset (Droplet, Space, or otherwise) created by other DigitalOcean customers are not to be tested under any circumstances.**",
"impact": "Out of scope"
},
{
"type": "wildcard",
"endpoint": "*.doserverless-dev3.io",
"description": null,
"impact": "Out of scope"
},
{
"type": "wildcard",
"endpoint": "*.ondbaasdev.com",
"description": null,
"impact": "Out of scope"
},
{
"type": "wildcard",
"endpoint": "*.onstagingocean.app",
"description": null,
"impact": "Out of scope"
},
{
"type": "other",
"endpoint": "Marketplace Apps and Add-Ons",
"description": "The marketplace applications and add-ons are maintained by our partnered vendors. \nSecurity issues against these components of the marketplace are not in the scope of this program and ineligible for bounty rewards, but we are happy to help facilitate communications to the application owners.\nPlease reach out to us at security@digitalocean.com for facilitation.",
"impact": "Out of scope"
},
{
"type": "other",
"endpoint": "Other DigitalOcean open source projects not listed",
"description": "All open source projects hosted by DigitalOcean not otherwise listed as in-scope are out-of-scope.",
"impact": "Out of scope"
}
]
}
}Assets created by other DigitalOcean customersMarketplace Apps and Add-OnsOther DigitalOcean open source projects not listed