generated: '2026-07-19' method: searched probe: true source: https://www.dell.com/.well-known/security.txt docs: https://www.dell.com/support/contents/en-us/article/product-support/self-support-knowledgebase/security-antivirus/alerts-vulnerabilities/dell-vulnerability-response-policy note: >- Avamar has no product-specific disclosure program; it is covered by the Dell Technologies PSIRT and the Dell products bug bounty program. program: Dell Product Security Incident Response Team (Dell PSIRT) policy: - https://www.dell.com/support/dell-vulnerability-response-policy - https://www.dell.com/support/contents/en-us/article/product-support/self-support-knowledgebase/security-antivirus/alerts-vulnerabilities/dell-vulnerability-response-policy contact: - https://bugcrowd.com/dell-product - https://bugcrowd.com/dell-com - https://www.dell.com/support/dell-vulnerability-response-policy bug_bounty: platform: Bugcrowd programs: - name: Dell Technologies' Products Bug Bounty Program url: https://bugcrowd.com/dell-product scope: Dell-branded or currently supported products (the program covering Avamar) - name: Dell Technologies Application Bug Bounty url: https://bugcrowd.com/dell-com scope: Dell applications and websites encryption_key: https://www.delltechnologies.com/asset/en-us/products/security/legal-pricing/dell-psirt-pub-key.txt canonical: https://www.dell.com/.well-known/security.txt security_txt: expires: '2026-04-17T04:00:00.000Z' expired: true last_modified: '2025-04-17' finding: >- The published security.txt Expires field is 2026-04-17, which had already passed when this probe ran on 2026-07-19. Per RFC 9116 an expired security.txt should not be relied upon; the referenced policy and Bugcrowd programs remain live. reporting_channels: - channel: Bugcrowd detail: Security researchers submit product vulnerability reports through the Dell Bugcrowd site. - channel: Dell PSIRT email detail: >- Industry groups, vendors and other reporters without Technical Support access, or who do not want to go through the bug bounty program, can send reports directly to Dell PSIRT. Sensitive contents should be PGP-encrypted with the published Dell PSIRT key. - channel: Dell Technical Support detail: >- Enterprise and commercial product customers and partners report through their Technical Support team, who engage the product team and Dell PSIRT. response_commitments: acknowledgement: within 3 business days of receipt update_cadence: every 30 calendar days or less standards_alignment: - FIRST PSIRT Services Framework - ISO/IEC 29147:2018 - ISO/IEC 30111:2019 memberships: - FIRST (Forum of Incident Response and Security Teams) - SAFECode (Software Assurance Forum for Excellence in Code) evidence: - source: https://www.dell.com/.well-known/security.txt kind: security.txt (live probe, HTTP 200) - source: https://www.dell.com/support/contents/en-us/article/product-support/self-support-knowledgebase/security-antivirus/alerts-vulnerabilities/dell-vulnerability-response-policy kind: vulnerability response policy - source: https://bugcrowd.com/dell-product kind: bug bounty program