At BlackRock, we take cybersecurity seriously and value the contributions of the security community at large. The responsible disclosure of potential issues helps us ensure the security and privacy of our customers and their data.
If you believe you have identified a potential security issue, please send it to us in accordance with our Responsible Disclosure Guidelines and include the following information:
Researchers shall disclose potential vulnerabilities in accordance with the following guidelines:
By responsibly submitting your findings to BlackRock in accordance with these guidelines BlackRock agrees not to pursue legal action against you. BlackRock reserves all legal rights in the event of noncompliance with these guidelines.
Once a report is submitted, BlackRock commits to provide prompt acknowledgement of receipt of all reports and will keep you reasonably informed of the status of any validated vulnerability that you report through this program.
Certain vulnerabilities are considered out of scope for our Responsible Disclosure Program. Out-of-scope vulnerabilities include:
When reporting a potential vulnerability, please include a detailed summary of the vulnerability, including the target, steps, tools, and artifacts used during discovery (screen captures welcome).
BlackRock uses HackerOne to triage and validate responsibly disclosed vulnerability reports.
Please submit your report via HackerOne - https://hackerone.com/blackrock
Submitting your report via HackerOne will help ensure timely validation.
If you are unable to report via HackerOne, you may email us at responsible.disclosure@blackrock.com