This document applies only to the Groove service, accessed at [subdomain].groovehq.com. It does not govern the Helply service. For Helply's current legal terms, see the Terms of Service and Privacy Policy.
Introduction
Groove appreciates the effort of software security researchers who work to make the Internet more secure. Our security vulnerability bounty system exists to reward the work of security researchers who find issues with our software and web services.
If you have questions about this program or are unable to properly access or test an in-scope asset, email support@groovehq.com with the subject prefix VDP:.
Rules
- Test only to the extent necessary to confirm the vulnerability.
- Use accounts and data that you own or have explicit permission to use.
- Do not publicly disclose the vulnerability until Groove has confirmed remediation or agreed to a disclosure timeline with you.
- Do not use social engineering or target Groove employees, contractors, customers, or vendors.
- Do not conduct denial-of-service, distributed denial-of-service, resource-exhaustion, scraping, brute-force, spam, or other high-volume automated testing.
- Do not perform destructive testing, deploy persistence mechanisms, or modify or delete data.
- Do not access, copy, download, or retain more customer or sensitive data than is strictly necessary to confirm the vulnerability.
If you encounter customer data, credentials, personal information, or other sensitive data, stop testing immediately. Do not continue accessing or reviewing the data. Report the exposure promptly to support@groovehq.com, explain what you encountered, and securely delete any locally retained copies after we confirm they are no longer needed for the investigation.
Safe harbor
Groove considers security research conducted in good faith and in accordance with this Groove program to be authorized. If your research and disclosure comply with this program:
- We will not initiate or support legal action against you for the research.
- We will not pursue a claim under the U.S. Computer Fraud and Abuse Act or the anti-circumvention provisions of the U.S. Digital Millennium Copyright Act for actions that were necessary to conduct the research.
- If a third party initiates legal action against you in connection with compliant research, we will take reasonable steps to make it known that your research was conducted in accordance with this program.
This safe harbor does not apply to actions outside this Groove program, does not authorize activity that violates applicable law, and cannot bind independent third parties. If you are unsure whether a planned test is permitted, contact us before proceeding.
Eligibility for a bounty
To qualify for a bounty:
- You must be the first reporter of the vulnerability and it must not be a duplicate or known issue
- Your report must be within scope and not on our list of ineligible reports and known issues
- You must not be a minor
- You must not be a resident of or be located in a country on any U.S. sanctions lists
Public disclosure of the issue before its resolution will result in disqualification from the Groove program. Evidence of abuse or accessing another user's data or account without their permission will also result in disqualification from the program.
Reporting
Send all legacy Groove vulnerability reports to support@groovehq.com with the subject prefix VDP:. Reports should include the following information to be considered for a bounty. Reports missing the information below will be marked as "Needs More Information," resulting in a minor loss of reputation points.
- Vulnerable URL(s) and any affected parameters
- Your browser and operating system
- Detailed, step-by-step explanation of how to replicate the issue
Screenshots or videos of the vulnerability are highly encouraged and will result in quicker triaging of the issue and possibly a higher bounty at Groove's discretion.
Scope
- www.groovehq.com
- api.groovehq.com
- *.groovehq.com
Eligible reports
Here is an incomplete list of reports we are interested in:
- Cross-site scripting (XSS)
- Directory traversal
- Privilege escalation
- Server-side remote code execution or command injection
- SQL or NoSQL injection
- Access control bypass
- Presence or disclosure of secret access tokens
Ineligible reports or known issues
The following reports are ineligible to receive bounties or reputation points. Any submitted reports related to them will be closed as N/A.
- Social engineering of Groove staff, contractors, or customers
- Reports from automated tools or scans
- Issues related to software or protocols not under Groove's control
- Denial of Service attacks, including mass requests against password reset, login, account creation, or other endpoints. We have monitoring and mitigation against brute force attacks which we believe are adequate. Please do not conduct brute force attacks.
- HTML or CSS injection in editor features - this is by design so that our users can have rich, styled content. We sanitize JavaScript and arbitrary code using sanitize-html. We are interested in reports about the execution of JavaScript though!
- Presence of autocomplete on form fields, including username and password fields
- SPF, DKIM, or DMARC settings
- Password and account recovery policies, including password reset emails and password reset links
- Reports noting the lack of or suggesting the institution of a password policy, including account lockout settings
- Email spoofing
- DNSSEC settings
- Presence of public (
pk.*) access tokens in web pages or URLs - due to their use in client-side JavaScript these are public by design. - Username enumeration, including an oracle that discloses whether a given username or email address is associated an account
- Reports of CSRF or reports of a lack of CSRF tokens on www.groovehq.com, unless accompanied by a detailed proof of concept exploit. We have alternative CSRF mitigation in place.
- Missing HTTP security headers, unless accompanied by a detailed proof of concept exploit that leverages their absence
- Existence of access-controlled administrative pages
- Reports related to the SSL/TLS certificate for www.groovehq.com
- Open redirects
- Use of a known-vulnerable library (without evidence of exploitability)
- Vulnerabilities only affecting older browsers.
- HSTS or CSP headers
- Content spoofing or HTML injection, unless accompanied by a proof of concept that demonstrates a security risk beyond injecting plain text
- Reports of insecure SSL/TLS ciphers or weak signature algorithms, unless accompanied by a working proof of concept of an exploit
Ineligible for monetary bounty, but appreciated
The following reports are ineligible for a cash bounty due to their low severity. If accompanied by a detailed proof of concept of an exploit leveraging their existence they may be eligible for a cash bounty at Groove's discretion.
- Mixed content
- Self-XSS