External Product Security Officer Program
ABOUT THE PROGRAM
As cybersecurity threats continue to evolve, DJI is committed to building a more comprehensive security ecosystem through collaboration with external security experts. The External Product Security Officer Program establishes long-term, in-depth partnerships with talented security researchers to continuously enhance the security of DJI products and services.
This program goes beyond DJI's traditional Bug Bounty approach by offering a structured framework for dedicated security testing initiatives. Through this program, researchers will have the opportunity to conduct in-depth security assessments on specific DJI products with dedicated resources and support from the DJI security team.
HOW IT WORKS
Invitation-based
Security researchers with a history of responsible reporting and meaningful contributions through the DJI Bug Bounty Program.
Periodic Testing Initiatives
DJI launches testing projects periodically targeting specific products. When an initiative is launched, DJI will notify participants via email.
Product Funding
DJI provides purchase funding for test products. Researchers are encouraged to source official DJI product(s) for testing independently.
Testing and Reporting
Invited researchers are required to provide testing results and feedback within two months after the project funding is disbursed. If special circumstances arise, participants must communicate with DJI's security team at least 10 business days before the deadline to report any delays in submission.
All vulnerabilities discovered during testing may be consolidated into a single report and submitted through the official DJI security submission portal: https://security.dji.com/en.
Vulnerability Rewards
DJI provides rewards based on findings according to vulnerability assessment criteria.
TIMELINE
Testing initiatives are launched as they arise. Detailed timeline information, including launch dates, testing windows (typically within two months of funding disbursement, unless specified otherwise), submission deadline, and reward evaluation schedule, will be provided via email upon each initiative launch.
TERMS AND CONDITIONS
All requirements and regulations of this program are subject to the DJI Security Researcher Guidelines: [guideline]
Participants are required to sign the Program Cooperation Agreement before participation. The agreement will be sent via email upon initial invitation.
If a security researcher violates the terms of this program (including but not limited to unauthorized disclosure, testing beyond authorized scope, engaging in malicious behavior, etc.), DJI has the right to:
(1) Require the researcher to refund all project funding and rewards already paid;
(2) Terminate the cooperation and cancel future qualifications to participate in this program.
CONTACT US
For inquiries, applications, or more information about the External Product Security Officer Program, please reach out to: bugbounty@dji.com
Our security team will be happy to discuss partnership opportunities and answer any questions you may have.
FAQ
Q: Who can participate in this program?
A: This is an invitation-only program targeting security researchers with a proven track record of responsible reporting and significant contributions to security research.
Q: Do I need to provide my own testing equipment?
A: No. DJI will provide invited researchers with funding at no cost to cover the purchase of official DJI product(s) for testing.
Q: What happens if I find a vulnerability?
A: Report it through the designated channels specified in your testing guidelines. DJI will assess the finding and provide rewards according to our vulnerability assessment criteria.
Q: Can I disclose vulnerabilities publicly?
A: No. All findings must remain confidential until DJI provides written approval for disclosure. This ensures all vulnerabilities are addressed before they become public, protecting user privacy and security.
Q: How long does the vulnerability assessment process take?
A: Timeline varies depending on the complexity of the findings. Participants will be updated on assessment progress.
Q: When will the next testing initiative be launched?
A: Testing initiatives are launched as they arise. We recommend subscribing to email notifications or contacting bugbounty@dji.com to stay informed about upcoming initiatives.