FedRAMP Environment Users: If you are participating in a program hosted on Bugcrowd’s FedRAMP environment, all support requests must be directed through the FedRAMP-specific channels described on this page. Do not use the standard Bugcrowd Support ticketing portal, as it operates outside the FedRAMP authorization boundary.
Contacting FedRAMP Support
For any issues, questions, or inquiries related to your participation in a Bugcrowd FedRAMP program, send an email to fedrampsupport@bugcrowd.com.
Our support team will review your request and respond to your request.
What to Include in Your Email
To help us resolve your issue quickly, please include the following details where applicable:
- Subject line: A brief description of the issue (e.g., “Submission not updating – Program XYZ”)
- Program name or ID: The name or identifier of the program you are participating in
-
Submission URL: A direct link to the relevant submission in the platform (e.g.,
https://tracker.bugcrowd.com/...) - Platform details: Any relevant context such as the affected feature, workflow step, error message, or browser/environment information
- Steps to reproduce: A clear sequence of actions that led to the issue, if applicable
What NOT to Include
To protect program integrity and comply with FedRAMP data handling requirements, do not include sensitive information in your support email. This includes:
- Full vulnerability details, exploit code, or proof-of-concept (PoC) content — share the submission URL instead
- Authentication tokens, API keys, session cookies, or passwords
- Personally identifiable information (PII) beyond what is needed to identify your account
- Target system credentials or internal network details
- Any data subject to export controls, regulatory restrictions, or classification markings
If your issue requires sharing sensitive details, our support team will provide a secure channel for you to submit that information after your initial request is received.
Notes
- The standard Bugcrowd Support ticketing portal is not available for FedRAMP environment users, as it is not within the FedRAMP authorization boundary.
- All communications related to FedRAMP programs should remain within approved, compliant channels.
- If you are unsure whether your issue involves sensitive information, err on the side of caution and omit it from the initial email. Our team will guide you through a secure submission process if needed.