Vulnerability Testing Environment Program
Vulnerability Testing Environment Program
We also provide the “vulnerability testing environment program" so that you can conduct tests safely without considering any impact on the production environment.
Program Overview
Application
Please apply from the following form.
We will contact you within 2 business days of your application to your registered e-mail address regarding the Vulnerability Testing Environment.
We may take longer to respond 5-7 business days during the year-end and New Year's holidays.
Participating in the Vulnerability Testing Environment Program in Conjunction with the Cybozu Bug Bounty Program
If you are already participating in the Bug Bounty Program, you can request access to a testing environment at the Reporting Site. If you do not have an account for the Reporting Site, please agree to the terms and conditions of the testing environment when you request an account using the Reporting Site Account Request Form.
Program Eligibility
Anyone who wishes to test product vulnerabilities is eligible.
For example, those who:
- Wish to access a testing environment before starting to use a service
- Wish to test the vulnerability of customizations
- Wish to access a testing environment to participate in the Bug Bounty Program
Cost
Free of charge.
Availability
The testing environment is available year-round.
However, if the testing environment is not accessed for more than 6 months, the environment will be deleted after the user has been contacted by email.
Application Requirements
・You agree with the terms and conditions of the application.
・You can communicate in Japanese or English.
・You are not an employee of Cybozu Inc. or its subsidiary companies.
・You can provide equipment available to access a tested environment. There are no restrictions on what kind of equipment can be used.
Services and Products We Provide
Cloud Services
With the bug bounty testing environment program, we provide a system that is on physically separate servers and lines from the production environment. You can conduct tests safely without considering any impact on the production environment.
cybozu.com Administration
- cybozu.com Administration
・For details, refer to "cybozu.com Help"
Client Certificate Authentication
・For details, refer to the help page "Using Client Certificate Authentication"
Cybozu Office on cybozu.com
For details, refer to "Cybozu Office User Help" and "Cybozu Office Administrator Help" in the following Japanese Web sites:
Cybozu Office User Help Cybozu Office Administrator HelpGaroon on cybozu.com
For details, refer to "Cybozu Garoon User Help" or "Cybozu Garoon Administrator Help" in the following Web sites:
Cybozu Garoon User Help Cybozu Garoon Administrator Helpkintone
kintone
For details, refer to "kintone User Help" and "kintone Administrator Help" in the following Web sites:
kintone Administrator Help kintone User Helpkintone API (REST API, JavaScript API), User API
For details, refer to kintone developer program
Mailwise on cybozu.com
For details, refer to "Cybozu Garoon User Help" or "Cybozu Mailwise Administrator Help" in the following Web sites:
Cybozu Mailewise User Help Cybozu Mailwise Administrator HelpNotes
1. Do not conduct testing with the purpose of putting load on the test environments.
2. Services provided through the bug bounty testing environment program are running in "debug mode". If an error occurs on a service that is running in "debug mode", detailed information about the error will be displayed on the screen. The information on such error screens is provided for our debugging, and it is out of scope from your vulnerability testing.
3. The bug bounty testing environment will be down once a month for scheduled maintenance. We will notify you in advance of the maintenance, but the notification may be sent at the last minute due to circumstances beyond our control. Please also note that the maintenance may be performed multiple times during a month due to emergencies such as unscheduled maintenance.
Contact us
Frequently Asked Questions (FAQ)
Please check the frequently asked questions and answers before contacting us.
FAQContact Us
You can contact us at the Reporting Site with any questions or requests regarding the Bug Bounty Program.
If you do not have an account, please contact us using the form below.
https://cy-psirt.form.kintoneapp.com/public/inquery