Nike’s mission is to bring inspiration and innovation to every athlete in the world. For athletes to thrive, they track their performance and they need to know their data is being protected. We're obsessed with protecting their data. We take vulnerabilities that pose a security risk seriously, and we appreciate the global security research community’s help identifying risks.
Our responsible disclosure policy provides clear research guidelines—we ask that you play by the rules and within the scope of our program.
We accept submissions for the following domains and systems.
Sites
Apps (iOS and Android)
Submissions should be for vulnerabilities that pose a demonstrable risk potentially affecting our systems, users, or data. Best practice submissions are appreciated but may not receive a response.
Remember, if you encounter any sensitive information or PII, stop and notify us immediately.
Only interact with accounts you own or have explicit permission from the account owner. Feel free to create your own accounts for testing purposes.
Actions affecting the integrity or availability of authorized systems are prohibited. If you notice performance interruption or degradation, immediately suspend all use of automated tools.
The following methods are not authorized and constitute unacceptable conduct:
Here’s what we expect from you:
And here’s what you can expect from us:
Please use our Responsible Disclosure Form to submit the requested information.