generated: '2026-09-06' method: searched probe: true scope: >- Autodesk-wide. PowerMill is an Autodesk product (x-parent: autodesk) and does not run its own disclosure programme; Autodesk's programme explicitly covers "Desktop and mobile applications" and "any Autodesk-owned system, application, or service", which is what PowerMill is. policy: - https://hackerone.com/autodesk contact: - https://hackerone.com/autodesk programme: platform: HackerOne handle: autodesk url: https://hackerone.com/autodesk launched_publicly: '2025-01-27' submission_state: open offers_bounties: false offers_swag: true offers_thanks: true researcher_count: 279 resolved_report_count: 1215 safe_harbor: true response_targets: first_response_business_days: 2 time_to_triage_business_days: 2 time_to_resolution: depends on severity and complexity of the vulnerability in_scope_note: >- "Autodesk welcomes report of vulnerabilities affecting any Autodesk-owned system, application, or service. This includes but is not limited to: Web applications; Desktop and mobile applications; API and cloud services." out_of_scope_note: >- "Versions of desktop applications that are either not officially supported or do not have the latest patch versions installed" — this makes the Autodesk available-product-versions policy part of the security contract; see lifecycle/autodesk-powermill-lifecycle.yml. security_txt: served: false note: >- No /.well-known/security.txt is served on autodesk.com, www.autodesk.com or help.autodesk.com (403/404 — see well-known/autodesk-powermill-well-known.yml). The 200 on health.autodesk.com is Atlassian's Statuspage document, not Autodesk's. evidence: - source: https://hackerone.com/autodesk kind: bug-bounty-programme http_status: 200 fetched: '2026-09-06' detail: >- JSON programme record returned: id 20022, handle "autodesk", submission_state "open", 9,675-character published policy including Response Targets, Scope and Safe Harbor sections. - source: https://www.autodesk.com/trust/overview kind: programme-declared-website http_status: 403 fetched: '2026-09-06' detail: >- Named as the programme's website in the HackerOne profile record. www.autodesk.com returns 403 to non-browser clients (Akamai bot policy) — an edge policy, not a missing page.