generated: '2026-08-29' method: searched source: https://www.acceldata.io/bug-bounty url: https://www.acceldata.io/bug-bounty probe: url: https://www.acceldata.io/bug-bounty status: 200 fetched: '2026-08-29' note: >- probe-security-programs.py reported vdp=none because Acceldata serves no /.well-known/security.txt on any host and runs no HackerOne / Bugcrowd / Intigriti program. The program is real, first-party and self-hosted — reached from the site footer as "Bug Bounty" — so this file upgrades the probe result to searched. program: type: bug-bounty hosted: self-hosted platform: none url: https://www.acceldata.io/bug-bounty contact: bugbounty@acceldata.io contact_method: email intake: >- "To participate in our bug bounty program, kindly reach out via email to bugbounty@acceldata.io. Detailed instructions on the next steps will be provided upon receipt of your email." rewards: offered: true published_amounts: false basis: severity stated: >- "Acceldata values the timely disclosure of potential security vulnerabilities found on our platform and will provide a reward for the reporting of in-scope vulnerabilities that lead to mitigation. Rewards will be based on severity and range." scope_published: false safe_harbor_published: false response_sla_published: false security_txt: published: false hosts_probed: - host: www.acceldata.io status: 404 - host: documentation.acceldata.io status: 404 - host: docs.acceldata.io status: 200 note: SPA shell, not a document - host: accounts.acceldata.app status: 403 - host: api.acceldata.app status: 403 gap: >- A researcher who follows RFC 9116 finds nothing. The program exists but is discoverable only from a footer link, so a single /.well-known/security.txt naming bugbounty@acceldata.io and the program URL would close the gap outright. related: trust_center: https://trust.acceldata.io/ security_and_network_compliance: https://docs.acceldata.io/documentation/security-and-network-compliance