ThoughtSpot is committed to the security of our products and the protection of our customers' data. We value the work of security researchers who help us identify vulnerabilities before malicious actors can exploit them. This program establishes the framework for reporting security vulnerabilities and outlines expectations for both researchers and ThoughtSpot throughout that process.
We request that the security community give us an opportunity to fix the reported vulnerabilities before releasing information with/to any third parties. ThoughtSpot will not pursue legal action against those researchers that follow the below guidelines and responsibly disclose any security vulnerabilities directly to ThoughtSpot. ThoughtSpot reserves all legal rights in the event of noncompliance with these program guidelines.
| Asset | Details |
|---|---|
| ThoughtSpot Cloud | *.thoughtspot.cloud, *.thoughtspot.com production services |
| Mobile Applications | iOS and Android apps |
| Developer Platform | REST APIs, Embedded Analytics, SpotDev |
| Public Repositories | github.com/thoughtspot public repos |
| Authentication & SSO | Where ThoughtSpot controls the implementation |
To qualify for recognition or rewards, researchers must adhere to the following:
ThoughtSpot will not initiate or support legal action against researchers for security research conducted in accordance with this program. Specifically, ThoughtSpot:
Important: This safe harbor applies only to ThoughtSpot's own legal claims. ThoughtSpot cannot and does not authorize testing of third-party systems and cannot bind customers, cloud providers, or other third parties. If you are uncertain whether a specific action is permitted, contact us before proceeding.
Submission portal: https://bugspot.thoughtspot.com/
Please include the following in your report:
| Field | Description |
|---|---|
| Vulnerability type | e.g., “SQL Injection in ThoughtSpot Cloud REST API” |
| Affected component | Specific URL, API endpoint, feature, or module |
| Severity assessment | Your CVSS v3.1 score + vector string |
| Reproduction steps | Exact steps from unauthenticated or authenticated state |
| Proof of concept | Screenshots, screen recording, or code |
| Impact description | What data/functionality is at risk and for whom |
| Contact information | For follow-up, pseudonymous acceptable |
| Suggested mitigations | Optional but appreciated |
Reports missing reproduction steps or impact descriptions will be deprioritized.
ThoughtSpot does not permit any disclosure of findings without prior written consent from ThoughtSpot. Researchers must keep all vulnerability details, including the existence of a reported vulnerability, confidential at all times.
All valid reports meeting the criteria above are eligible for public recognition in ThoughtSpot's Security Acknowledgement page, with researcher consent. Attribution includes name or alias and vulnerability category.
| Vulnerability Category | Reward Eligibility |
|---|---|
| RCE, auth bypass, tenant data exposure | Monetary reward at ThoughtSpot's discretion based on impact and report quality |
| All other valid in-scope findings | Hall of fame acknowledgment |
| Vulnerability Severity | Bounty Amount |
|---|---|
| Critical | 500 USD |
| High | 200 - 500 USD |
| Medium & Low | No Bounty |
Rewards are not issued for: vulnerabilities already known to ThoughtSpot, out-of-scope findings, reports that violate the rules of engagement, or automated scanner output without manual validation.
* Severity of reported vulnerability will be calculated again using CVSS Score by considering security controls in place for the ThoughtSpot environment.
Any unauthorized activity outside the terms of this program may be subject to legal action pursuant to applicable laws and company policies. If, at any time, you have concerns or are uncertain whether your security research is consistent with the terms of this program, stop testing and contact [email protected]. Email communication between you and ThoughtSpot, including without limitation emails you send to ThoughtSpot reporting a potential security vulnerability, should not contain any of your proprietary information. The contents of all email communication you send to ThoughtSpot shall be considered non-proprietary. ThoughtSpot, or any of its affiliates, may use such communication or material for any purpose whatsoever, including, but not limited to, reproduction, disclosure, transmission, publication, broadcast, and further posting. By submitting any information, you grant ThoughtSpot a perpetual, royalty-free, and irrevocable right and license to use, reproduce, modify, adapt, publish, translate, distribute, transmit, publicly display, publicly perform, sublicense, create derivative works from, transfer, and sell such information. This program does not grant researchers any right, title, or interest in ThoughtSpot intellectual property.
This program is governed by the laws of the State of California. ThoughtSpot reserves the right to update this program at any time; material changes will be published with an updated effective date. This program applies globally. Researchers are responsible for ensuring their testing activities comply with applicable laws in their jurisdiction.