Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Opsgenie
Opsgenie Bugcrowd $100–$4,000
3 more reviews needed for a grade
Write a review Claim this company profile

Work at Opsgenie? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Reviews

0 published

No reviews yet.

Be the first to review

Program profile Bugcrowd · imported

Facts published by Bugcrowd on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 4 Oct 2026.

Opsgenie is a modern incident management platform for operating always-on services, empowering Dev & Ops teams to plan for service disruptions and stay in control during incidents. With over 200 deep integrations and a highly flexible rules engine, Opsgenie centralizes alerts, notifies the right people reliably, and enables them to collaborate and take rapid action. Throughout the entire incident lifecycle, Opsgenie tracks all activity and provides actionable insights to improve productivity and drive continuous operational efficiencies. Get Started (tl;dr version) Testing for Opsgenie is to be performed on https://*.opsgenie.com using free-trial accounts. Do not access, impact, destroy or otherwise negatively impact Opsgenie customers, or customer data in anyway. Ensure that you use your @bugcrowdninja.com email address. Ensure you understand the targets, scopes, exclusions, and rules below. Quick Links Opsgenie Links Website https://docs.opsgenie.com/docs/welcome https://docs.opsgenie.com/docs/opsgenie-quick-start-guide https://docs.opsgenie.com/docs/new-user-guide Docs https://docs.opsgenie.com/ For real time support you can also use Intercom chat bubble on bottom right of www.opsgenie.com API Docs https://docs.opsgenie.com/docs/api-overview https://docs.opsgenie.com/docs/api-access-management https://docs.opsgenie.com/docs/authentication https://docs.opsgenie.com/docs/alert-api https://docs.opsgenie.com/docs/user-api Mobile apps (Android) https://play.google.com/store/apps/details?id=com.ifountain.opsgenie (iOS) https://itunes.apple.com/us/app/opsgenie/id528590328 Focus Areas Authentication Session Management HTTP and Cookie Security Multi Tenant Data Leakage/Access Server-side Remote Code Execution (RCE) Server-Side Request Forgery (SSRF) Stored/Reflected Cross-site Scripting (XSS) Injection XML External Entity Attacks (XXE) Access Control & Authorization Vulnerabilities Path/Directory Traversal Issues File Upload & File hosting Ensure you review the out of scope and exclusions list for further details. ** Cross Instance Data Leakage/Access refers to unauthorised data access between instances. Creating Your Instance Researchers can sign up here: https://www.atlassian.com/software/opsgenie/try Note: Remember to use your @bugcrowdninja.com email address !! Do not forget to verify your account by clicking on the link via email, some features will not work until verification is complete. !! Additional documents: https://docs.opsgenie.com/docs/welcome https://docs.opsgenie.com/docs/opsgenie-quick-start-guide https://docs.opsgenie.com/docs/quick-set-up-video https://docs.opsgenie.com/docs/new-user-guide https://docs.opsgenie.com/docs/users Disclosure Request Guidance Submissions that meet the following requirements will be considered for disclosure upon request: The submission has been accepted The reported vulnerability has been fixed and released in production The submission does not regard a customer instance or a customer’s account

Currency
USD
Submissions
Open
Launched
Feb 2019
Scope entries
7 Bugcrowd’s count

Scope

7 assets
AssetTypeEligibilityMax severity
*.opsgenie.com website ✓ bounty not set
app.opsgenie.com website ✓ bounty not set
mobileapp.opsgenie.com website ✓ bounty not set
Opsgenie (Android) android ✓ bounty not set
Opsgenie (IoS) ios ✓ bounty not set
Show all 7 assets
AssetTypeEligibilityMax severity
Any internal or development services. website out not set
Opsgenie Production (billing systems, third parties) website out not set