Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Cloud Software Group
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Cloud Software Group? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 22 Sep 2026.

What it pays, by severity

Critical no reports on record
High no reports on record
Medium no reports on record
Low no reports on record

$543,499 paid to researchers in total, $250 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
34
in 90 days
Resolved
not published
all time, last one 22 days ago
Participants
208
hunters engaged
Response efficiency
29%
below its own targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 15 days 33–37
25 Aug 34 reports 22 Sep

Response targets it sets itself

First response
3 days
Triage
5 days
Bounty
30 days
Resolution
30 days

A target the program declared, not a measurement of it being met.

Getting in the door

Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.

Over 31 days (17 snapshots): intake down 3 reports; response efficiency down 2 points; 90-day payout down $1,750.

See how this programme’s report load compares to others →

Reviews

0 published

No reviews yet.

Be the first to review

Who this program credits

222 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 proabiral 2,749 127 / 157 81%
2 rhynorater 1,672 82 / 90 91%
3 streaak 1,360 45 / 64 70%
4 melar_dev 1,280 61 / 68 90%
5 floerer 735 20 / 28 71%
6 zonduu 729 37 / 46 80%
7 todayisnew 675 36 / 75 48%
8 arneswinnen 623 14 / 14 100%
9 stillwater 591 24 / 72 33%
10 pesticide 549 17 / 32 53%
11 dkd 519 25 / 49 51%
12 hogarth45 515 20 / 29 69%
13 stfuanu 453 29 / 39 74%
14 godiego 447 30 / 47 64%
15 d0xing 416 17 / 31 55%
16 qu1nten 413 14 / 17 82%
17 jaypatel 383 19 / 21 90%
18 defmax 238 16 / 28 57%
19 gammarex 232 6 / 8 75%
20 txt3rob 231 8 / 10 80%
21 sumgr0 220 19 / 29 66%
22 jmxy 189 6 / 7 86%
23 bayotop 168 4 / 4 100%
24 damif512 165 5 / 7 71%
25 vulnh0lic 149 8 / 12 67%

Showing the top 25 of 222 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 16 Sep 2026.

Responsiveness
23% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Oct 2020
Scope entries
53 HackerOne’s count

Scope

53 assets
AssetTypeEligibilityMax severity
(yoursubdomain).sf-api.com URL ✓ bounty Critical
(yoursubdomain).sf-api.eu URL ✓ bounty Critical
(yoursubdomain).sharefile.com URL ✓ bounty Critical
(yoursubdomain).sharefile.eu URL ✓ bounty Critical
*.citrixworkspacesapi.net URL ✓ bounty Critical
Show all 53 assets
AssetTypeEligibilityMax severity
accounts.cloud.com URL ✓ bounty Critical
adm.cloud.com URL ✓ bounty Critical
ap-s.cloud.com URL ✓ bounty Critical
api.adm.cloud.com URL ✓ bounty Critical
api.sharefile.com URL ✓ bounty Critical
api.sharefile.eu URL ✓ bounty Critical
Citrix End Point Analysis (EPA) client for Linux OTHER ✓ bounty Critical
Citrix End Point Analysis (EPA) client for Windows OTHER ✓ bounty Critical
Citrix Secure Access client for Android GOOGLE PLAY APP ID ✓ bounty Critical
Citrix Secure Access client for iOS OTHER ✓ bounty Critical
Citrix Secure Access client for Linux OTHER ✓ bounty Critical
Citrix Secure Access client for macOS APPLE STORE APP ID ✓ bounty Critical
Citrix Secure Access client for Windows OTHER ✓ bounty Critical
eu.cloud.com URL ✓ bounty Critical
http://(yoursubdomain).sharefile.com/sf/v3/ URL ✓ bounty Critical
onboarding-*.cloud.com URL ✓ bounty Critical
onboarding.cloud.com URL ✓ bounty Critical
secure.sharefile.com URL ✓ bounty Critical
secure.sharefile.eu URL ✓ bounty Critical
sf-rp-eu.sharefile.com URL ✓ bounty Critical
sf-rp-us.sharefile.com URL ✓ bounty Critical
sf-rp.sharefile.com URL ✓ bounty Critical
us.cloud.com URL ✓ bounty Critical
(youriwssubdomain).cloud.com URL out None
(yoursubdomain).ap.iws.cloud.com URL out None
(yoursubdomain).eu.iws.cloud.com URL out None
(yoursubdomain).us.iws.cloud.com URL out None
*.browser.cloud.com OTHER out None
*.citrix*.com URL out None
*.cloudburrito.com URL out None
*.podio.com URL out None
*.securevdr.com URL out None
*.sharefile.com URL out None
*.sharefile.eu URL out None
*.sharefile*.com URL out None
*.sharefile*.eu URL out None
*.xmdev.cloud.com URL out None
*.xmqa.cloud.com URL out None
*.xmtest.cloud.com URL out None
*developer.cloud.com URL submit only None
accounts-internal.cloud.com URL out None
citrix.cloud.com URL out None
citrixworkflows.sharefile.com URL out None
citrixworkflows.sharefile.eu URL out None
Enterprise Sync, ShareFile Desktop for Mac, ShareFile Desktop Widget DOWNLOADABLE EXECUTABLES out None
http://(subdomain).sharefile.com/rest/ URL out None
launch.cloud.com URL out None
www.cloud.com URL out None