generated: '2026-08-13' method: searched probe: true source: https://birdeye.com/security/ policy: - https://birdeye.com/security/ contact: - security@birdeye.com bug_bounty: program: null platform: null note: >- No HackerOne, Bugcrowd or Intigriti program found. Birdeye runs a direct-report channel rather than a public bounty. security_txt: served: false probed: - {url: 'https://birdeye.com/.well-known/security.txt', status: 404} - {url: 'https://docs.birdeye.com/.well-known/security.txt', status: 404} - {url: 'https://mcp.birdeye.com/.well-known/security.txt', status: 404} - {url: 'https://api.birdeye.com/.well-known/security.txt', status: 401} note: >- No RFC 9116 security.txt on any Birdeye host, despite a real, staffed disclosure channel. Adding one is a cheap, high-value fix for Birdeye. program: reporting_channel: mailto:security@birdeye.com page_language: >- "Contact Security / Report a Vulnerability — Have a security question or found a vulnerability? We want to hear from you. Disclose securely" related_practices: - Secure SDLC with code review and dependency scanning - Annual third-party penetration testing - SSO, SCIM and role-based access control (RBAC) evidence: - source: https://birdeye.com/security/ kind: security-page http_status: 200 fetched: '2026-08-13' keywords: [report a vulnerability, disclose securely, security@birdeye.com, penetration testing] - source: https://trust.birdeye.com/ kind: trust-center http_status: 200 fetched: '2026-08-13'