generated: '2026-09-04' method: searched source: https://security.kanyun.com/ name: Kanyun Security Response Center (YSRC / 看云安全应急响应中心) program: present: true operator: Kanyun Holdings Group (看云控股集团) — Yuanfudao's parent group url: https://security.kanyun.com/ alternate_url: https://security.yuanfudao.com/ platform: Tencent xSRC (self-hosted instance, "Powered by Tencent xSRC") platform_url: https://security.tencent.com/index.php/xsrc type: self-hosted vulnerability disclosure program with rewards bug_bounty: true reward_model: >- Points ("安全币" / security coins) redeemable for cash and merchandise, plus quarterly awards. The public gift catalog lists a 100 CNY cash redemption at 100 coins and branded merchandise at 39 coins. contact: email: security@kanyun.com submission_url: https://security.kanyun.com/user.php?m=user&c=post&a=add auth_required_to_submit: true auth_methods: - QQ login - WeChat login policy: url: https://security.kanyun.com/index.php?a=view&c=page&id=14 title: 看云安全应急中心(YSRC)标准漏洞处理及评分标准 (YSRC standard vulnerability handling and scoring standard) version_observed: V1.3 (page id=14, published 2024-04-02); V1.7 is the current version linked from the homepage testing_rules_url: https://security.yuanfudao.com/index.php?m=&c=page&a=view&id=2 testing_rules_title: SRC 行业安全测试规范 (industry security testing code of conduct) sla: triage: within 1 business day (status moves to "审核中" / under review) assessment: within 3 business days (severity rating and coin award, or rejection) scope: statement: >- Products and business systems operated by Kanyun Holdings Group, including but not limited to the wildcard domains listed below, plus the group's servers and its published PC, mobile and mini-program clients. The policy text explicitly excludes classup-related vulnerabilities. in_scope_domains: - '*.zhenguanyu.com' - '*.yuanfudao.com' - '*.yuantiku.com' - '*.yuansouti.com' - '*.xiaoyuankousuan.com' - '*.banmaaike.com' - '*.ybccode.com' - '*.skypeople.com' - '*.gridcoffee.com' - '*.moliyuezi.com' - '*.motiff.com' excluded: - classup (vulnerabilities no longer accepted) security_txt: served: false note: >- No /.well-known/security.txt is served on yuanfudao.com, www.yuanfudao.com or security.kanyun.com — all probed 2026-09-04 and returned 404. The disclosure program is discoverable only through the human-facing YSRC portal, not through RFC 9116. x-evidence: fetched: '2026-09-04' probes: - url: https://security.kanyun.com/ http_status: 200 note: YSRC portal homepage, live - url: https://security.yuanfudao.com/ http_status: 301 note: redirects to https://security.kanyun.com/ - url: https://security.kanyun.com/index.php?a=view&c=page&id=14 http_status: 200 note: scoring standard V1.3, carries the in-scope domain list - url: https://www.yuanfudao.com/.well-known/security.txt http_status: 404 notes: - >- The program covers the whole Kanyun group, not Yuanfudao alone. Domains named in its scope that belong to sibling brands (motiff.com — Motiff AI design tool; gridcoffee.com — Grid Coffee; skypeople.com) are recorded here as published scope, not as Yuanfudao properties. - >- This is a security-reporting surface, not an API. It is the only machine-addressable developer- facing program Yuanfudao/Kanyun publishes.