Vulnerability Reporting Terms
Last Updated: September 2025
These Terms govern the Tanium CNA and Bug Bounty program and supersede HackerOne’s guidelines and terms in case of conflicting statements. Tanium’s Bug Bounty program has certain supplemental terms and scope requirements identified below. By submitting a vulnerability under either program, you acknowledge and agree to the following Terms.
Reporting Guidelines
- Provide detailed reports with reproducible steps. Be sure to include the name and version number of the impacted Tanium product, the nature and impact of the suspected issue, and any associated evidence or PoC as necessary.
- Social engineering (e.g. phishing, vishing, smishing) is prohibited.
- Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with the explicit permission of the account holder.
- Securely destroy any confidential information you may have obtained.
- You grant to Tanium all rights necessary to the reports.
- You have read and agreed to the Tanium Vulnerability Disclosure Policy and acknowledge that Tanium retains full discretion to interpret and apply the terms of the program, including any individual’s eligibility for or modification of program rewards.
- You have authority to participate in this program and that you have obtained from your employer all authorizations necessary to receive the prizes awarded, and that in doing so, you are in compliance with all applicable laws, regulations, and your employer’s policies regarding the acceptance of any rewards.
Out of Scope
When reporting vulnerabilities, please consider the attack scenario/exploitability and the security impact of the bug. For example, the following issues are considered out of scope:
- Clickjacking on pages with no sensitive actions.
- Unauthenticated/logout/login CSRF.
- Missing configuration best practices without a working Proof of Concept.
- Denial of Service (DoS) attacks against our web properties.
- Spam or social engineering techniques.
- Tanium Labs content.
- Vulnerabilities in third-party Tanium integrations including applications, services, or sensors.
- Vulnerabilities that are only exploitable if someone intentionally misconfigures, insecurely configures, or insecurely deploys our products.
- Vulnerabilities in generic implementations of technologies or libraries that we implement. In some cases, Tanium leverages third-party technologies in limited ways to implement our solutions. Vulnerabilities in generic implementations of third-party technologies are out of scope unless a vulnerability is determined to exist in Tanium’s implementation.
Safe Harbor
Any activities conducted in a manner consistent with this policy will be considered conduct authorized by Tanium. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.
Bug Bounty Reporting Guidelines
Vulnerabilities submitted through Tanium's Bug Bounty program are also subject to these additional Reporting Guidelines:
- If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.
- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.
- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).
- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.
- Participation in Tanium’s program does not create an employment relationship.
Bug Bounty Scope
The following resources are in scope for Bug Bounty:
- Any vulnerability included in the Tanium CNA scope
- Customer specific domains related to the ‘bugbounty’ customer instance. These are
- bugbounty.cloud.tanium.com
- bugbounty-api.cloud.tanium.com
- portal.bugbounty.cloud.tanium.com
- Any public facing website on the tanium.com domain (e.g. tanium.com, developer.tanium.com, docs.tanium.com) not explicitly related to a specific customer.
The following resources are out of scope for Bug Bounty testing:
- Tanium cloud hosted or on-premise resources belonging to a specific Tanium customer. This includes all domains matching the following patterns:
- *.cloud.tanium.com
- *-api.cloud.tanium.com
- portal.*.cloud.tanium.com
Bug Bounty Rewards
Our rewards are based on a variety of factors, including severity per the CVSSv3 (Common Vulnerability Scoring Standard) and impacted asset. Please note that these are general guidelines, and reward decisions are up to the discretion of Tanium.
The following individuals may not qualify for certain rewards including monetary awards:
- Tanium employees and contractors, and any other workers performing services for Tanium.
- Employees and contractors of Tanium customers or pending customers, and any other workers performing services for a Tanium customer or pending customer who identify a vulnerability as part of their normal job responsibilities.
- Residents of any embargoed and sanctioned countries as promulgated by the United States Government, which currently include Cuba, Iran, North Korea, Syria, Russia, Belarus, and certain covered regions of Ukraine and any other Specially Designated Nationals as identified by the U.S. Office of Foreign Assets Control, as may be updated from time to time.
- The immediate family members of, or individuals residing in the same household as, any of the individuals described above.
Thank you for helping keep Tanium and our users safe!