Brief overview

Zendesk engages with security researchers who report vulnerabilities as described here. We validate, respond to, and fix vulnerabilities where appropriate to support our commitment to security and privacy. We don’t take legal action against, suspend, or terminate access to the service for people who discover and responsibly report security vulnerabilities. Zendesk reserves all legal rights in the event of noncompliance.

How can I participate?

If you’re a security researcher and discover a security vulnerability in our services, disclose it responsibly. We also provide monetary and reputation rewards for eligible reports via Bugcrowd at https://bugcrowd.com/engagements/zendesk.

If you’re a customer or a prospective customer and discover a security vulnerability, report it per the instructions in our responsible disclosure policy. This includes any vulnerabilities that a penetration test by you or a third party might find.

Where can I find more information?

This article gives a brief overview of Zendesk’s bug bounty program. For full details, see the official post https://bugcrowd.com/engagements/zendesk.

Powered by Zendesk