generated: '2026-08-01' method: searched probe: true source: https://www.kaseya.com/trust-center/vulnerability-disclosure-policy/ policy: - https://www.kaseya.com/trust-center/vulnerability-disclosure-policy/ - https://hackerone.com/kaseya contact: - mailto:disclosures@kaseya.com - https://www.kaseya.com/trust-center/engage-with-us/ - https://www.kaseya.com/trust-center/security/report/ bug_bounty: program: HackerOne url: https://hackerone.com/kaseya paid: true reward_range: USD 101 – 10,101 reward_basis: monetary recognition for vulnerability reports with significant business impact, paid at time of fix exclusions: active and former Kaseya employees and their families are ineligible safe_harbor: true safe_harbor_note: Good-faith research consistent with the program is authorized with respect to applicable anti-hacking laws; Kaseya waives the relevant Terms of Service and Acceptable Usage Policy restrictions for in-scope research. scope: in_scope: - any Kaseya-owned web service that handles sensitive user data - Kaseya mobile applications - Kaseya hardware devices - '*.kaseya.com' - '*.autotask.net' - '*.dattobackup.com' out_of_scope: - third-party hosted sites - tools.datto.com - cpkg.datto.com security_advisories: https://www.kaseya.com/trust-center/security/ pgp_key: null security_txt: false security_txt_note: Kaseya publishes no /.well-known/security.txt on any owned host — see well-known/kaseya-well-known.yml. The 200 at status.kaseya.com/.well-known/security.txt belongs to Atlassian Statuspage, not Kaseya. evidence: - source: https://www.kaseya.com/trust-center/vulnerability-disclosure-policy/ kind: disclosure-policy-page fetched: '2026-08-01' keywords: - vulnerability disclosure policy - safe harbor - hackerone - disclosures@kaseya.com - bug bounty - source: https://www.kaseya.com/legal/ kind: legal-index-link fetched: '2026-08-01'