Notice on Security Testing Conduct Standards


2026-08-31 DJI


In accordance with the DJI Bug Bounty Program Terms and applicable laws and regulations, security researchers are required to strictly adhere to the Minimum Necessity Principle and the Data Non-Retention Principle during vulnerability verification. The specific requirements are as follows:


I. Minimum Necessity Principle


  • Researchers may only collect the minimum amount of data necessary to demonstrate the existence and actual impact of a vulnerability (e.g., a single record or a redacted screenshot). Testing must cease immediately once the vulnerability is confirmed, and the scope of verification must not be expanded further;

  • Any form of bulk, continuous, or automated data extraction is strictly prohibited, as are credential stuffing, brute-force attacks, and other high-frequency probing activities;

  • When handling sensitive personal information — including names, phone numbers, geographic locations, and biometric data — researchers should present findings in a redacted or masked format to avoid full exposure.

II. Data Non-Retention Principle


  • Downloading, retaining screenshots of, disseminating, selling, or disclosing to any third party any data obtained during testing is strictly prohibited. Researchers must not forward, display, or discuss such data with any third party — including colleagues, other security researchers, or media — through any channel, including social media, forums, online communities (e.g., WeChat groups, QQ groups, Telegram), internal messaging tools, or public presentations;

  • All data generated during testing (including logs, cached files, and exported data) must be immediately and permanently deleted upon submission of the report and must not be retained on local devices or any third-party storage medium;

  • If data beyond the scope required for verification is inadvertently obtained during testing, researchers must proactively disclose the reason, scope, and disposal method in their report, and cooperate with DJI to complete data deletion and verification.

III. Consequences of Non-Compliance


Any data collection or handling that exceeds the boundaries described above does not constitute legitimate security testing. Upon confirmation of a violation, DJI will take the following measures based on the severity of the conduct:


  • Issue a formal warning, require remediation within a specified timeframe, and disqualify the researcher from receiving the bounty reward for the relevant submission;

  • For more serious violations, add the researcher to DJI's security testing blacklist, suspending or permanently revoking their eligibility to participate in future Bug Bounty Program activities;

  • For severe violations that may constitute a breach of applicable laws and regulations — including the Cybersecurity Law of the People's Republic of China and the Personal Information Protection Law — DJI reserves the right to pursue civil, administrative, or criminal liability as permitted by law.

For any questions, please contact us through the following channel:


Email: bugbounty@dji.com



DJI Security Response Center

August 31, 2026