Back to bounty boardSafe harbor Good-faith testing inside the published scope is authorised. Disclosure First reply typically under a day. Intake Policy intake Scope rules
DA
Vulnerability disclosure program
DANA
dana.id / public reporting path
Full+CVD5 signal
Both mobile apps and two web hosts. Development, CMS and internal hosts are all out.
In scope
- m.dana.id
- mgs.dana.id
- Android app: id.dana
- iOS app: DANA
Out of scope
- Social engineering against staff or customers
- Physical intrusion or on-site testing
- Denial of service, load testing or resource exhaustion
- Credential brute force or password spraying
- Unthrottled automated scanning
- Accessing data belonging to real users
- scope.UNLISTED_SUBDOMAINS
- scope.DEV_AND_CMS_HOSTS
Scope rules
What Rooted expects in a valid report
In scope
Owned public web assets, auth/session logic, exposed APIs, account boundaries, sensitive data exposure and clear misconfiguration with reproducible impact.
Out of scope
Social engineering, physical testing, spam, denial of service, brute force, persistence, malware, extortion language and access to data that is not yours.
Report quality
Include affected asset, severity, exact steps, observed impact and safe evidence. We score reports faster when the reproduction is clean.
Verification
Rooted reviews the submission and may coordinate with the listed program. Points are released only after the finding is confirmed.