All assets owned by or attributable to Dropboxother· No BountyThird-party systems or domains referencing Dropboxother— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Dropbox Vulnerability Disclosure Program .
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"id": "b31aef04-c63f-429f-b965-f92c94e5eec3",
"name": "Dropbox Vulnerability Disclosure Program ",
"company_handle": "dropbox",
"handle": "dropbox-vdp",
"url": "https://www.intigriti.com/programs/dropbox/dropbox-vdp/detail",
"status": "open",
"confidentiality_level": "public",
"tacRequired": false,
"twoFactorRequired": false,
"min_bounty": {
"value": 0,
"currency": "USD"
},
"max_bounty": {
"value": 0,
"currency": "USD"
},
"targets": {
"in_scope": [
{
"type": "other",
"endpoint": "All assets owned by or attributable to Dropbox",
"description": null,
"impact": "No Bounty"
}
],
"out_of_scope": [
{
"type": "other",
"endpoint": "Third-party systems or domains referencing Dropbox",
"description": "Before testing or reporting a vulnerability, confirm that the target asset is owned or managed by Dropbox. Terms like “Dropbox-compatible” do not mean Dropbox controls the system. If you're unsure, contact the program team to avoid interacting with assets outside of scope at bugbounty@dropbox.com.",
"impact": "Out of scope"
}
]
}
}