Policy

Freshworks understands that protection of customer data is a significant responsibility and requires the highest priority. We genuinely value the assistance of security researchers and any others in the security community to assist in keeping our systems secure. The responsible disclosure of security vulnerabilities helps us ensure the security and privacy of all our users.

 

 
Reporting Guidelines

Please provide the following details on the report

Domains in Scope
  • *.freshworks.com
  • *.freshdesk.com
  • *.freshservice.com
  • *.freshsales.io
  • *.freshcaller.com
  • *.freshchat.com
  • *.freshmarketer.com
  • *.freshconnect.io
  • *.freshping.io
Qualifying Bugs                                                               
Non-Qualified Bugs
Bounty Eligibility

Freshworks has partnered with HackerOne for the responsible disclosure program. Refer to https://hackerone.com/freshworks for more information about the program. Please report the vulnerabilities in the below scope only via HackerOne.

Any asset/scope apart from the above will not be eligible for bounty payout. The bounty decision is made per freshworks internal policies. The bounty payment will be fulfilled via HackerOne.

Hall of Fame

While Freshworks does not provide any reward for responsibly disclosing unique vulnerabilities and working with us to remediate them, we would like to publicly convey our deepest gratitude to the security researchers.  We will add your name to our Hall of Fame.  Your legendary efforts are truly appreciated by Freshworks.

We would like to recognise the efforts of the following individuals for their contribution to our responsible disclosure program. Please accept our sincerest gratitude to every one of you.

2023
  • Varshini Ramesh
  • Ramkumar G
  • Udhaya Prakash
  • Mohd Kashif
  • Lave Kumar
  • Vishwas Reddy
2022
  • Akash Singh
  • Saddam Hussain
  • Yash Kumar Verma
  • X-Samurai
  • Devender Rao(in/devender-rao)
  • Robin De Smet (Kautz.io)
  • Thirumalaivasan Candassamy
2010 - 2021
  • Gopikrishna
  • Neeraj Sonaniya
  • Samir Hadji
  • Rojan Rijal
  • Marek Szustak
  • Vignesh Jothiraj
  • Deepali Sarjerao Malekar
  • Prasanna P R
  • John Steven Bullecer
  • Havoc Guhan
  • Muthukumar Marikani
  • Ratnadip Gajbhiye
  • Virendra Yadav
  • Ahsan Khan
  • Allan Jay Dumanhug
  • Nor Win
  • Paulos Yibelo
  • Kalpesh Makwana
  • Georgie Yoxall
  • Abdul Rehman
  • Koutrouss Naddara
  • Lokesh Kumar
  • Ranjeet Singh
  • Sir Root
  • Rafael Pablos
  • Nithish Varghese
  • Shivam Kumar Agarwal
  • Sreehari Haridas
  • Zeyad Khaled
  • Babar Khan
  • Varun Kakumani
  • Md. Nur A Alam Dipu
  • Gaurang Bhatnagar
  • Naveen Sihag
  • Andy Linux
  • Eddy Abrar
  • Kamran Saifullah
  • Mehul Mohan
  • Jay Patel
  • Kacper Szurek
  • Dhayalan B Dhayalan
  • Eusebiu Blindu
  • Deepankar Arora
  • Wordfence
  • Pankaj Rane
  • Yaroslav Olejnik
  • Vinoth Kumar
  • Kunal arora
  • Cristian Joseph D. Legacion
  • Atul Shedage
  • Babita Ram
  • Subramanian
  • Harry M. Gertos
  • Apurve Jain
  • Kamil Sevi
  • Robbie Wiggins
  • Nishtaa chandak
  • Nicholis du Toit
  • Krishnaraj Ramalingam
  • Karl Aparece
  • Tarun Sehgal
  • Hasan Khan
  • Sushil Sunil Ainani
  • Adesh Anand
  • Samuel Valmiki
  • PRATIK V. GAIKWAD
  • லுஃவாஃதிளயுஙிள் (rboxtjwlsso)
  • Oscar Arnflo
  • Bishal Khadka (Chandu)
  • Offensive Bug Hunter(Sovon Bhattacharya)
  • GoodData Security Team
  • Sakthivel Swaminathan