generated: '2026-07-31' method: searched probe: true source: https://unqork.com/security/ description: >- Unqork publishes a self-hosted vulnerability disclosure program (VDP) at unqork.com/security. Reports go to a dedicated PSIRT mailbox, an armored PGP public key is published for encrypted submissions, and the page defines an explicit in-scope / out-of-scope surface plus a Hall of Fame. Unqork states it "may elect to provide a reward" depending on severity — there is no third-party bug bounty platform (HackerOne / Bugcrowd / Intigriti) involved. policy: - https://unqork.com/security/ contact: - psirt@unqork.com pgp: published: true location: https://unqork.com/security/ format: armored PGP public key block, inline on the disclosure page bounty: platform: null self_hosted: true reward: >- Discretionary, based on severity — "we may elect to provide a reward or add your name and social media contact to our hall of fame". hall_of_fame: https://unqork.com/security/ report_requirements: - Summary of the finding - Steps to reproduce - Proof of Concept (POC) - Impact of the finding - Nuclei Templates scope: in_scope: - '*.unqork.com' - marketplace.unqork.io - The Unqork No-Code Platform qualifying_vulnerabilities: - Server-side Remote Code Execution (RCE) - NoSQL Injection - Stored Cross Site Scripting (XSS) - Authentication Bypass - Unintentional data access between environments - Designer and Express RBAC vulnerabilities - Server-Side Misconfiguration out_of_scope: - www.unqork.com - Customer environments and Unqork employees - Automated scanner output / automated scans against in-scope environments - HTTPS configuration such as insecure TLS algorithms - HTTP headers (Content Security Policy, clickjacking/XSS protection) - Email DNS records (SPF, DKIM, DMARC) and certificate issuance (CAA) - Malicious code introduced by designers to attack Express users - Self-XSS - Reflected inputs with no impact to the end user or server - Denial of Service (DOS) and Distributed Denial of Service (DDOS) - Spamming, Flooding, Rate Limiting - Social engineering against Unqork employees or contractors - Username / e-mail enumeration tooling: >- A Burp Suite configuration file covering the two in-scope domains is offered for download (last updated 07/13/2022). response_commitment: >- Unqork states it aims to rapidly respond and verify a reported vulnerability, replies directly after receiving a disclosure, then updates the reporter periodically with response and remediation status. security_txt: present: false note: >- No /.well-known/security.txt (RFC 9116) was served on any Unqork host — unqork.com answers 200 with the marketing SPA for every /.well-known/ path, docs.unqork.io returns 404, developers.unqork.io returns 403 from S3. The disclosure program exists only as an HTML page. Publishing a security.txt that points at https://unqork.com/security/ and psirt@unqork.com would be a one-line win. evidence: - source: https://unqork.com/security/ kind: disclosure-page fetched: '2026-07-31' http_status: 200 keywords: - responsible disclosure - psirt@unqork.com - PGP public key - hall of fame - scope / out of scope