Authorization & Scope
Authorization Framework
Hollow Ground only processes workspace clone requests that fall within a platform's published bug bounty scope. This page documents the authorization basis for each supported platform.
SoGood
Program type: Open bug bounty
Authorization basis: SoGood's publicly accessible bug bounty program authorizes security research against their platform, including workspace-level inspection by registered researchers.
Scope: All workspace types accessible to a registered user account under standard terms.
Exclusions: Production infrastructure not accessible via the standard API; third-party integrations outside SoGood's control surface.
How We Verify
For open programs like SoGood, we verify that the program is active and the requested asset class is in scope at the time of your submission. We log the program URL, scope version, and verification timestamp in every manifest.
For invite-only programs, we require you to provide proof of invite (program acknowledgment email) before processing. We do not store this proof beyond the verification step.
Chain-of-Custody
Each zip delivery includes a `manifest.json` signed with the request's unique id, the researcher's handle, the platform, the scope reference, and the SHA-256 hash of the zip contents. This manifest is your evidence that the clone was obtained under authorized conditions.
Responsible Disclosure
By submitting a request, you confirm that you are using the exported workspace solely for authorized security research, that you will handle any discovered vulnerabilities per the platform's responsible disclosure policy, and that you will not redistribute the zip contents beyond what is required for your report.
Questions
Email hollow-ground@sogoodmail.co with your program details. We respond to authorization questions before you submit.