- English
- Français
- Deutsch
- Contact us
- Docs
- Login
Active version 2.0 | Updated 03 September 2025
Upsun is a Platform-as-a-Service where customers can host their applications and make them available to the world without worrying about the "how".
At Upsun, we take the security of our platform seriously. We appreciate the work of security researchers and welcome responsible disclosure that helps us protect our customers and our infrastructure.
This Vulnerability Disclosure Program (VDP) is not a public bug bounty program
Our goal is to give security researchers a clear, simple and safe way to report vulnerabilities affecting Upsun or Blackfire.
This program allows you to responsibly disclose potential vulnerabilities without fear of legal consequences, provided you follow our guidelines.
When testing or reporting, you must:
If you follow these rules, we commit to:
The following assets operated directly by Upsun, Platform.sh or Blackfire:
If the domain contains more than one subdomain level, it is almost certainly a customer application and out of scope.
Examples:
The following are always out of scope:
Upsun operates as a PaaS where customers can host their applications and leverage our tooling to enhance their productivity.
According to our shared responsibility model, customers are responsible for the security of their applications so customer applications will always be out of scope for the purpose of this program.
Examples include:
Research against those vendors should be reported directly to them.
Including but not limited to:
Full reference: HackerOne Core Ineligible Findings
We do not process these reports and they will never result in a reward or invitation.
When submitting a report, please include:
Please do not include real data samples such as PII, cardholder data or other sensitive information. Provide only the information needed for validation.
We strongly discourage the excessive or uncritical use of LLMs to generate reports.
Low-effort AI-generated reports will be rejected immediately and will not result in an invitation to our private program.
If you use an LLM, ensure the content is accurate, concise and validated manually
Please submit all reports through the contact listed in our security.txt file:
Before reporting, double-check:
Low-impact or purely theoretical issues will not be accepted.
We maintain a private bug bounty program on HackerOne.
It is invitation-only and focused on impactful vulnerabilities.
If you believe your expertise could be valuable, feel free to include your HackerOne username
Researchers who demonstrate strong signal, quality and impact may receive an invitation.
We appreciate the time and effort researchers invest in helping us secure Upsun.
Your responsible disclosure helps protect our users, our platform, and the broader ecosystem.
Active version 2.0 | Updated 03 September 2025
Previous version: Responsible Disclosure Program, version 1.0