HackerOne · VDP

Allegion Vulnerability Disclosure Program

Complete guide to Allegion's vulnerability disclosure program on HackerOne. View in-scope assets, reward amounts, response times, and tips for finding vulnerabilities.

Program Overview

Allegion runs a vulnerability disclosure program on HackerOne. The program has 134 in-scope assets and is managed by HackerOne's triage team.

134
In-Scope Assets
4h
Avg Response
80%
Efficiency
100d
Avg Resolve

In-Scope Assets

AssetTypeMax SeverityEligible
*.allegion.comWILDCARDCriticalNo Bounty
*.allegionengage.comWILDCARDCriticalNo Bounty
*.isonaspureaccesscloud.comWILDCARDCriticalNo Bounty
*.my-mobilekey.comWILDCARDCriticalNo Bounty
*.yonomi.coWILDCARDCriticalNo Bounty
9500IQ / 2800IQ Senior Swing Series OperatorsOTHERCriticalNo Bounty
Aero USB RFID ReaderHARDWARECriticalNo Bounty
BLEGateway (IF-4041)HARDWARECriticalNo Bounty
CISA Aero PMS Service (Windows)OTHERCriticalNo Bounty
CISA Reader App (Windows)OTHERCriticalNo Bounty
CISA Reader App (iMac)OTHERCriticalNo Bounty
Domo Connexa ButtonHARDWARECriticalNo Bounty
Encoder 2HARDWARECriticalNo Bounty
Interflex Managed Services (cloud)OTHERCriticalNo Bounty
Interflex Software IF-6020OTHERCriticalNo Bounty
Interflex Software IF-6040OTHERCriticalNo Bounty
Interflex Software SP-EXPERTOTHERCriticalNo Bounty
Interflex Terminals access controlHARDWARECriticalNo Bounty
Interflex Terminals time recordingHARDWARECriticalNo Bounty
Interflex controllersHARDWARECriticalNo Bounty
Interflex desktop readers and encodersHARDWARECriticalNo Bounty
MyEVO Lock ControllerHARDWARECriticalNo Bounty
MyEVO RFID TransponderHARDWARECriticalNo Bounty
OpenX Wall ReaderHARDWARECriticalNo Bounty
OpenX eCylinderHARDWARECriticalNo Bounty
OpenX eHandleHARDWARECriticalNo Bounty
Schlage CTE Single Door ControllerHARDWARECriticalNo Bounty
Schlage ControlHARDWARECriticalNo Bounty
Schlage EncodeHARDWARECriticalNo Bounty
Schlage GWE GatewayHARDWARECriticalNo Bounty
Schlage LE/LEBHARDWARECriticalNo Bounty
Schlage NDE/NDEBHARDWARECriticalNo Bounty
Smart Software 4OTHERCriticalNo Bounty
Von Duprin RU/RMHARDWARECriticalNo Bounty
Wall Reader 2HARDWARECriticalNo Bounty
XE360HARDWARECriticalNo Bounty
XE360 with RealSyncHARDWARECriticalNo Bounty
allegion.caURLCriticalNo Bounty
brio.com.auURLCriticalNo Bounty
brionz.comURLCriticalNo Bounty
briouk.comURLCriticalNo Bounty
briousa.comURLCriticalNo Bounty
com.allegion.IFkeyAPPLE_STORE_APP_IDCriticalNo Bounty
com.allegion.access.storeAPPLE_STORE_APP_IDCriticalNo Bounty
com.allegion.cisa.openxAPPLE_STORE_APP_IDCriticalNo Bounty
com.allegion.cisa.openxGOOGLE_PLAY_APP_IDCriticalNo Bounty
com.allegion.cisa.openx_keyGOOGLE_PLAY_APP_IDCriticalNo Bounty
com.allegion.cisa.openxkeyAPPLE_STORE_APP_IDCriticalNo Bounty
com.allegion.cisa.smartaccessAPPLE_STORE_APP_IDCriticalNo Bounty
com.allegion.cisa.smartaccessGOOGLE_PLAY_APP_IDCriticalNo Bounty

Showing 50 of 134 in-scope assets. View all on HackerOne.

Out-of-Scope Assets

  • staebapp01.allegion.com
  • stczpisupplier.allegion.com
  • stisupplier.allegion.com

Tips for Hacking Allegion

  1. Read the policy — Understand what's in scope, out of scope, and any specific testing restrictions before you start.
  2. Enumerate the attack surface — Use subdomain enumeration and directory bruteforcing to map all accessible endpoints.
  3. Focus on high-impact bugs — Look for SQL injection, SSRF, and IDOR vulnerabilities first.
  4. Test authentication flows — Check for OAuth misconfigurations and CSRF in login/signup flows.
  5. Write clear reports — Include steps to reproduce, impact assessment, and suggested remediation. Use Burp Suite to capture evidence.

Frequently Asked Questions

How do I start hacking Allegion?

Sign up on HackerOne, read the program policy carefully, review the in-scope assets listed above, and start testing. Always stay within scope and follow responsible disclosure guidelines.

Does Allegion pay bounties?

No, Allegion runs a Vulnerability Disclosure Program (VDP) without monetary rewards. You may receive recognition or swag.

What types of vulnerabilities does Allegion accept?

Allegion accepts reports for vulnerabilities found in their 134 in-scope assets. Common accepted vulnerability types include XSS, SQL injection, SSRF, IDOR, authentication bypass, and RCE. Check the program policy for specific exclusions.