Description

UpCloud is a European cloud service provider with it's HQ in Helsinki, Finland. The service started from simply offering virtual private servers for customers but covers now much more services, like managed databases and Kubernetes, load balancing, object storage and even private computing at 12 service areas around the world. This vulnerability disclosure program (VDP) is intended to provide you a way to report the issues you may have found on our platforms.

Bounties

This is a responsible disclosure program without bounties.

Rules of engagement
Not applicable
Not applicable
Not applicable
Not applicable

By participating in this program, you agree to:

  • Respect the Community Code of Conduct
  • Respect the Intigriti Terms and Conditions
  • Respect the scope of the program
  • Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo etc.)

Validation times

We will validate all submissions within the below timelines, once your submission has been verified by Intigriti.

Vulnerability Severity Time to validate
Exceptional 2 Working days
Critical 2 Working days
High 5 Working days
Medium 15 Working days
Low 15 Working days
Domains

*.upcloud.com

No bounty
Wildcard

Things relevant to UpCloud in general are in this scope

https://github.com/orgs/UpCloudLtd/repositories/*

No bounty
Wildcard

This scope exists to cover our public repositories residing in Github

In scope

Introduction

Welcome to our program! We understand that no technology is perfect and we're grateful for the work of our security researchers and community members in identifying any vulnerabilities. Your efforts help us ensure the security and privacy of our users.

Since this is a vulnerability disclosure program and not a bug bounty program, we don't have financial rewards for your findings. However, we believe in the value of community and the power of collective problem-solving and appreciate your efforts to maintain the integrity and security of our platforms.

Our worst-case scenarios are:

  • Breach of personal data of our customers
  • Breach of data stored by our customers in our service
  • Abuse of our APIs creating denial of service in a manner which we cannot easily filter/block (eg. ransoming us against service unavailability)

About UpCloud

UpCloud is an European cloud hosting company based in Helsinki, Finland which offers various cloud services from the usual virtual private servers to more managed products or services such as load balancers or databases, and even private cloud computing. To gain a better understanding of UpCloud it's recommended to check our company website for these purposes if you want to.

Feedback
Would you like to help us improve our program or have some feedback to share, please send your anonymous feedback here:
Program feedback link
Please note this form will be checked periodically and should not be used for submission or support queries.

Severity assessment

This program follows Intigriti's contextual CVSS standard

FAQ

Q: Are there any legal things I should consider when submitting a report?

A: Please see our safe harbor policy above for the findings.

Q: What rewards do you offer?

A: We do not offer rewards at the vulnerability program, however we are thankful for your findings.

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.