Core Assets In-Scope Products (for…tencent.com/index.php/policy)otherNon Core Assets In-Scope Products …tencent.com/index.php/policy)otherPlease note that the vulnerabiliti…not be eligible for bounties.other— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Tencent Bug Bounty Program.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"id": "tencent-bug-bounty-program",
"name": "Tencent Bug Bounty Program",
"public": true,
"disabled": false,
"managed": null,
"min_bounty": 8,
"max_bounty": 5000,
"targets": {
"in_scope": [
{
"target": "Core Assets In-Scope Products (for the full list please visit https://en.security.tencent.com/index.php/policy)",
"type": "other"
},
{
"target": "Non Core Assets In-Scope Products (for the full list please visit https://en.security.tencent.com/index.php/policy)",
"type": "other"
}
],
"out_of_scope": [
{
"target": "Please note that the vulnerabilities reported for the following assets will not be eligible for bounties.",
"type": "other"
},
{
"target": "*.qzoneapp.com",
"type": "other"
},
{
"target": "*. myqcloud.com",
"type": "other"
},
{
"target": "Third-party applications and websites",
"type": "other"
},
{
"target": "*Notes about Tencent Cloud (cloud.tencent.com as included in *.tencent.com)",
"type": "other"
},
{
"target": "Only vulnerabilities affecting the platform itself and IP owned by Tencent will be accepted. If an IP belongs to Tencent Cloud external customer, it is not considered in scope.",
"type": "other"
}
]
}
}*.qzoneapp.com*. myqcloud.comotherThird-party applications and websitesother*Notes about Tencent Cloud (cloud.…as included in *.tencent.com)otherOnly vulnerabilities affecting the…t is not considered in scope.other