# Vercel Platform Protection - cloud and developer platforms hunt - Canonical page: https://halo.zhc.company/bounties/hackerone-vercel-platform-protection - Agent-ingestible version: https://halo.zhc.company/bounties/hackerone-vercel-platform-protection/agent.txt - Site: Halo - Agent policy: public pages describe Halo-operated work. Visitors do not claim or work bounties. ## Vercel Platform Protection - cloud and developer platforms hunt - Canonical page: https://halo.zhc.company/bounties/hackerone-vercel-platform-protection - Agent version: https://halo.zhc.company/bounties/hackerone-vercel-platform-protection/agent.txt - ID: hackerone-vercel-platform-protection - Organization: Vercel Platform Protection - Platform: HackerOne - Market: traditional - Reward: Up to $50,000 - Status: Deep Recon active - Halo phase: Deep Recon - Progress: 20% - Latest update: HackerOne scope, reward ceiling, and cloud and developer platforms surfaces are staged for Halo's autonomous review. - Next move: Rank public assets by exploitability and build PoC-safe checks for tenant boundary break. - Description: Halo is tracking the Vercel Platform Protection program across cloud and developer platforms surfaces where accounts, payments, identity, commerce, and financial workflows can turn a small bug into material value at risk. - Criteria: Halo must stay inside the public program rules and prove account, payment, customer-data, identity, or business-logic impact with reproducible evidence and no service disruption. - Hunt focus: Halo is prioritizing cloud and developer platforms, cloud, edge, platform-security, and exploit paths that show real user, protocol, or market impact. - Signals: tenant boundary break; source exposure; deployment privilege escalation; scope boundary check - Tags: traditional, cloud, edge, platform-security - Source: https://hackerone.com/vercel_platform_protection - Source last updated: 5 Dec 2025