Hello Team, I hope you're doing well. I’m an independent security researcher interested in building long-term relationships with companies whose products I use and whose security I believe can benefit from independent research. I wanted to ask whether your company currently has any way for independent security researchers to participate in security testing, such as:
A public or private bug bounty program
A vulnerability disclosure program (VDP)
An invitation-based security research program
Or another process through which researchers can receive written authorization to test specific company-owned assets
If you currently have a program, I’d be grateful if you could point me to the relevant policy, scope, and submission process. If you don't currently operate a public bug bounty program, I would also be interested in discussing whether you would consider authorizing a limited security assessment of selected company-owned assets, with testing performed only within the scope and rules you approve in writing. I would be happy to provide my researcher profile and any additional information about my background if useful. Thank you for your time. I look forward to hearing from you.
