Unqork · Vulnerability Disclosure

Unqork Vulnerability Disclosure

Vulnerability disclosure

Unqork publishes a self-hosted vulnerability disclosure program (VDP) at unqork.com/security. Reports go to a dedicated PSIRT mailbox, an armored PGP public key is published for encrypted submissions, and the page defines an explicit in-scope / out-of-scope surface plus a Hall of Fame. Unqork states it "may elect to provide a reward" depending on severity — there is no third-party bug bounty platform (HackerOne / Bugcrowd / Intigriti) involved.

Unqork runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyNo-CodeLow-CodeApplication DevelopmentEnterprise SoftwarePlatform as a ServiceWorkflowFinancial ServicesInsuranceGovernmentApplication Modernization
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
psirt@unqork.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-31'
method: searched
probe: true
source: https://unqork.com/security/
description: >-
  Unqork publishes a self-hosted vulnerability disclosure program (VDP) at
  unqork.com/security. Reports go to a dedicated PSIRT mailbox, an armored PGP
  public key is published for encrypted submissions, and the page defines an
  explicit in-scope / out-of-scope surface plus a Hall of Fame. Unqork states it
  "may elect to provide a reward" depending on severity — there is no
  third-party bug bounty platform (HackerOne / Bugcrowd / Intigriti) involved.
policy:
  - https://unqork.com/security/
contact:
  - psirt@unqork.com
pgp:
  published: true
  location: https://unqork.com/security/
  format: armored PGP public key block, inline on the disclosure page
bounty:
  platform: null
  self_hosted: true
  reward: >-
    Discretionary, based on severity — "we may elect to provide a reward or add
    your name and social media contact to our hall of fame".
  hall_of_fame: https://unqork.com/security/
report_requirements:
  - Summary of the finding
  - Steps to reproduce
  - Proof of Concept (POC)
  - Impact of the finding
  - Nuclei Templates
scope:
  in_scope:
    - '*.unqork.com'
    - marketplace.unqork.io
    - The Unqork No-Code Platform
  qualifying_vulnerabilities:
    - Server-side Remote Code Execution (RCE)
    - NoSQL Injection
    - Stored Cross Site Scripting (XSS)
    - Authentication Bypass
    - Unintentional data access between environments
    - Designer and Express RBAC vulnerabilities
    - Server-Side Misconfiguration
  out_of_scope:
    - www.unqork.com
    - Customer environments and Unqork employees
    - Automated scanner output / automated scans against in-scope environments
    - HTTPS configuration such as insecure TLS algorithms
    - HTTP headers (Content Security Policy, clickjacking/XSS protection)
    - Email DNS records (SPF, DKIM, DMARC) and certificate issuance (CAA)
    - Malicious code introduced by designers to attack Express users
    - Self-XSS
    - Reflected inputs with no impact to the end user or server
    - Denial of Service (DOS) and Distributed Denial of Service (DDOS)
    - Spamming, Flooding, Rate Limiting
    - Social engineering against Unqork employees or contractors
    - Username / e-mail enumeration
  tooling: >-
    A Burp Suite configuration file covering the two in-scope domains is offered
    for download (last updated 07/13/2022).
response_commitment: >-
  Unqork states it aims to rapidly respond and verify a reported vulnerability,
  replies directly after receiving a disclosure, then updates the reporter
  periodically with response and remediation status.
security_txt:
  present: false
  note: >-
    No /.well-known/security.txt (RFC 9116) was served on any Unqork host —
    unqork.com answers 200 with the marketing SPA for every /.well-known/ path,
    docs.unqork.io returns 404, developers.unqork.io returns 403 from S3. The
    disclosure program exists only as an HTML page. Publishing a security.txt
    that points at https://unqork.com/security/ and psirt@unqork.com would be a
    one-line win.
evidence:
  - source: https://unqork.com/security/
    kind: disclosure-page
    fetched: '2026-07-31'
    http_status: 200
    keywords:
      - responsible disclosure
      - psirt@unqork.com
      - PGP public key
      - hall of fame
      - scope / out of scope