Security Research Contributors

We take the protection of our customer data very seriously and we appreciate those who share Trust as our #1 value.

Appy wearing scouting uniform, waving in the forest

To make a responsible disclosure, learn more about our Responsible Disclosure Policy. On behalf of Salesforce, our customers, and our users, we would like to thank the following researchers for their contributions.

Extraordinary Research Contributions

Appy_Thank_You_1200x675.png

Hardest Hitting Bug Bounty Hackers

Congratulations to our Hardest Hitting Bug Bounty Hackers–the Bug Bounty Researchers who contributed the five most critical vulnerabilities of those reported to Salesforce’s Bug Bounty Program throughout the year. Salesforce Security Staff voted upon this distinguished award to recognize these researchers for upholding Salesforce’s #1 value, Trust.

2023

none_of_the_above

82af5ddffbb795

shubs

arneswinnen

luqii

2022

afewgoats

ajxchapman

arneswinnen

madinmars

none_of_the_above

2023

Bug Bounty Researchers

try_to_hack, g4mb4, micr0mind, d0xing, luckz, mmdz, 0x4m, honoki, d0nut, bugtriage-locke, gammarex, d3f4u17, amalyoman, holybugx, sim4n6, securitythinker, arneswinnen, damian89, val_brux, analyz3r, naaash, djurado, todayisnew, zeb0x01, yuvraj_dighe, hazimaslam, snorlhax, rg0x01, savik, none_of_the_above, juji, mateuszek, testingforbugs, youstin, fr4via, sumgr0, hafolife, lm_davidcburke, bustinjieber, foorw1nner, jin0ne, m0chan, protoneko, me9187, k57447, sachin_kr, afewgoats, ozgur, luqii, tolo7010, iqimpz, svennergr, w-, exploitmsf, kjsman, theokeen, c4rrilat0rr, zhongquanli, 0xdln, ngocdh, imgnotfound, 3th1c_yuk1, lowtechnaut, r3veal, darkdream, f6x, pesticide, jdchbdxmz, brdoors3, s3rdz0, pt200, 0xd0m7, lammy, mclaren650sspider, p4fg, daniel_v, mikey96, jaleel_khan_98, andrewrusso, indoappsec, mxnd, bonsoird, inhibitor181, arsene_lupin, hx01, jackds , shubs, nbabii, godiego, encryptsaan123, krevetk0, cache-money, alittleninja, imnarendrabhati, egrep, ibruteforce, rez0, ryotak, corb3nik, 82af5ddffbb795, archangel, spaceraccoon, rhynorater, gemini, corraldev, adi-agrawal, mooimacow, kcho, sowhatsec, dz_samir, dkd, ajxchapman, tess, proabiral, krynos, huyngoc, zhutyra, th3g3nt3lman, lukeberner, tuukkeli, segfo, akshyy, batee5a, ansariosama, renekroka, xsam, securify-bv, moti-h, bagipro, zere, 0xwise, anupamas01, thajeztah, o-siman, mheranco, 0x777, super-cert2, ian, norwegianwood, m4ll0k, pablofacciano, daik0n, hulk, jesus_pwn3d_u, gaurav-bhatia, goldenstone, le0w4ng, michael1026, bradleyjkemp, guyinhsv, mrrajputhacker2, freesec, s1ber, rz01, nickslow, hipotermia, jatindhankhar, fozgrkuggs3t, jusertestedd

2022 

Bug Bounty Researchers

0ang3el, 0x01alka, arneswinnen, d0xing, derision, djurado, dz_samiredivan, hazimaslam, honoki, inhibitor181, jinOne, krevetk0, m0chan, madinmars, melar_dev, michael1026, nadino, nagli, nbabii, ngocdh, p4fg, proabiral, ramsexy, ras-it, rz01, seifelsallamy, stealthy, svennergr, thecaffeinefix, todayisnew, tolo7010, try_to_hack, wirtha, youstin, zonduu 0xd0m7, 0xelkot, afewgoats, ahmedehane, ajxchapman, ak1t4, akshyyaksl337amad3u6, amaljacob, amsda, analyz3r, anandpingsafe, andi, andrewrusso, ansariosama, anupamas01, assassin_marcos, avezkhan, avram, bombon, brdoors3, bugra, caffeinefix, cakiki, chermysl, cocoh__23, codermak, comwrg, cyb3rz0n3, cygut, d0nut, d3f4u17, dirtycoder, dkd, dragonjar, egrep ehshahid, en_ahsanali, enzyro, fr4via, fracturedninja, fransrosen, freesecgofunch4x0r_dz, hackit0, hafolife, hailstorm1422, hk755a, hoangn14, holybugx, holyfield, homosec, hulk, huyngoc, hx01, ian, ignaciosarobe, imajes, imgnotfound, imnarendrabhati, iqbal_007, isimsiz, juji, kadusantiago, kotko, krynos, lehtu, m7mdharoun, malcolmx, manish_adz, mateuszek, melbadry9 michau, micr0mind, mikey96, mikkocarreon, mitchellwright, mr-hakhak, musab_alharanynaaashnaif_ksa, niraeth, none_of_the_above, not_stoppable, oxbo, pablofacciano, pankaj_kumar, paulcalabro, pesticide, polem4rch, realtess, recon_ninja, renekroka, rg0x01, rijalrojan, roberto99, rreiss, s3rdz0, s_p_q_r, salh4ckr, samlyhin, samux, shaikhyaser, sheikhimmi, sheikhrishad0, simontang, smaul, smitgharat0001, snorlhax sp00ka7x, spaceraccoon, stevenandres, th3g3nt3lman, txt3rob, villagelad, violet, vp40, w--, w2w, xsam, yuvraj_dighezanderziot


Independent Researchers

2019 -2020

0xd0m7, 0xcaptainfreak, 4bg0p, 0ang3elakhilmm, alexeypetrenko, alfazero, alittleninja, amontes, ankitkrdixit, ankitsingh, annunaki, anonym0us_py, anshuman_bh, apox, appsecure_in, arl_rose, arneswinnen, asad0x01_, ashish_r_padelkar, ateek, bejaminkm, bobrov, brdoors3, bubbounty, bugbasher, bughunterboy, c1231665, cdl, charityhackers, charlieeriksen, chernobyl, cmd-0_0, constructor2019, cr4xerbik4sh, cyb1, d0nut, d3n0, dataalchemist, delisyd, derision, dhakal_ananda, dkd, dvl, dz_samir, edoverflow, eelsivart, egrep, erbbysam, fishofprey, foobar7, frozensolid, goravseth, gujjuboy10x00, hack_all_things, hackdev16, harisec, hazimaslam, hdbreaker, httpsonly, indoappsec, inhibitor181, intidc, isecurity, jackds, jahin0x01, jepatel, jllis, jong_jong, jsadler01, kapytein, kasperkarlsson, kazan71p, kcho, khizer47, kusl, lagertha, lfb, linkks, luied1920, m7mdharoun, mantis, mattaustin, metnew, michael1026, mikee, mlitchfield, moshemiz, mr_r0w07, narenp, neema, ngalog, ngocdh, nih8l, none_of_the_above, nullboy, p4fg, paresh_parmar, pcastagnaro_sfdc, pen3t3r, piyushmalik, pnig0s, poutine_hero, prateek_0490, protector47, psaux, pufo, pxh3, quanyang, r0x33d, ramsexy, randbug101, randomdeduction, randomusername, ras-it, redguard, rijalrojan, ris, rubyroobs, rudnkh, ruvlol, rz01, samux, securitybreaker, securitythinker, sergeym, shahmeer-amir, shailesh4594, shepard, silenthunter, skavans, slechjke, smaury, smiegles, smsecurity, sniper302, sp1d3rs, stok, streaak, strukt, sub_super, suhas_gaikwad, sunil_yedla, sysecure, ta8ahi, tahaismail9, techguynoob, todayisnew, tolo7010, tophersmith116, try_to_hack, trying_to_hack, txt3rob, ubepkr, vinothkumar, vp40, vulnh0lic, wh11tew0lf, whitehatter, wirtha, yashrs, yotamc19899, z0mb13, zapprising, zephrfish, zeroflaw, zigoo0, ziot

Reminder: Please note that this page is updated annually. Starting in 2021, we will solely be recognizing researchers who submit valid reports to Salesforce. Suspect an issue? Privately share full details of the suspected vulnerability with the Salesforce Security team by emailing security@salesforce.com.