generated: '2026-07-25' method: searched probe: true source: https://cpaas.8x8.com/en/security/ program: runs_vdp: true runs_bug_bounty: true platform: HackerOne statement: >- "8x8 runs responsible disclosure and incentivized bounty programs through HackerOne to allow anyone to report vulnerabilities. With this National Institute of Standards and Technology best-practice responsible disclosure program, we have a well-defined process for finding and fixing vulnerabilities — before they could be exploited." policy: - url: https://hackerone.com/8x8-bounty name: 8x8 Bug Bounty Program (HackerOne) status: 200 - url: https://cpaas.8x8.com/en/security/ name: 8x8 CPaaS Security status: 200 - url: https://www.8x8.com/products/apis/security name: Security for 8x8 Communication APIs status: 429 status_note: www.8x8.com sits behind a Vercel security checkpoint that returns 429 to automated clients; the page is real and is linked from 8x8's own developer docs (developer.8x8.com/connect/docs/security-1). - url: https://www.8x8.com/why-8x8/security-and-compliance name: 8x8 Security & Global Compliance Standards status: 429 contact: [] contact_note: >- 8x8's CPaaS security page publishes a security contact address behind Cloudflare email obfuscation, so the literal address was not recovered and is not guessed here. Reports are accepted through the HackerOne programs above. security_txt: published: false probed: - {host: www.8x8.com, path: /.well-known/security.txt, status: 429} - {host: developer.8x8.com, path: /.well-known/security.txt, status: 404} - {host: api.8x8.com, path: /.well-known/security.txt, status: 404} - {host: sms.8x8.com, path: /.well-known/security.txt, status: 404} - {host: voice.8x8.com, path: /.well-known/security.txt, status: 404} note: No RFC 9116 security.txt was served from any 8x8 API or developer host. The disclosure program is real but is not machine-discoverable at /.well-known/security.txt. disclosed_reports_public: true disclosed_reports_note: 8x8 has publicly disclosed HackerOne reports (e.g. hackerone.com/reports/504122, hackerone.com/reports/1391576), evidence the program is operated rather than nominal. evidence: - source: https://cpaas.8x8.com/en/security/ kind: vendor security page keywords: [responsible disclosure, bounty, HackerOne, NIST] - source: https://hackerone.com/8x8-bounty kind: bug bounty program status: 200