This policy applies to the following systems and services:
- voteidaho.gov/*
- *.voteidaho.gov/*
- idahovotes.gov/*
- sos.idaho.gov/*
- *.sos.idaho.gov/* (with exception to the provided out-of-scope list)
The following sites subdomains are restricted from active vulnerability discovery, and are considered out-of-scope for the VDP program:
- Electiondesk.sos.idaho.gov/*
- Uat-elect.sos.idaho.gov/*
- Uat-enr.sos.idaho.gov/*
Any service not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this Policy’s scope and should be reported directly to the vendor according to their disclosure Policy (if any). If you aren’t sure whether a system is in scope or not, contact our reporting partner, the Election Infrastructure Information Sharing and Analysis Center (EI-ISAC) at [email protected] before starting your research.
Though we develop and maintain other internet-accessible systems or services, active research and testing must only be conducted on the systems and services covered by the scope of this document. If there is a particular system not in scope that you think merits testing, first contact us to discuss it. We aim to increase the scope of this Policy over time.