generated: '2026-07-31' method: searched probe: true source: https://www.boxabl.com/.well-known/security.txt description: >- BOXABL runs a real, publicly documented responsible-disclosure ("bug bounty") program. It is discoverable the correct way: an RFC 9116 security.txt at https://www.boxabl.com/.well-known/security.txt whose Contact field resolves to a published policy PDF. The policy defines scope, out-of-scope classes, rules of engagement, a safe-harbour clause, the submission channel and a discretionary CVSS-linked compensation model. This is notably more mature security-disclosure posture than most companies in the catalog that publish no API at all. Detail below was read from the policy PDF itself; the mechanical probe (0-working/probe-security-programs.py) independently confirmed the security.txt Contact hit. policy: - https://gcdn.boxabl.com/documents/bugbounty/Boxabl%20Policy.pdf contact: - bugs@boxabl.com - https://gcdn.boxabl.com/documents/bugbounty/Boxabl%20Policy.pdf program: type: self-hosted platform: null bounty: true bounty_model: >- Discretionary compensation determined by BOXABL, weighted by a CVSS-linked severity formula, report quality, internal risk assessment, prior-disclosure status (paid once per issue) and applicable sanctions legislation. safe_harbor: true safe_harbor_note: >- BOXABL states it will not pursue legal action against researchers who submit reports covering in-scope products through the approved channel and who follow the stated rules of engagement. coordinated_disclosure: true disclosure_note: >- Researchers are asked to refrain from public disclosure prior to a mutually agreed date; BOXABL commits to a timely initial response, open dialog on remediation timelines, and notification when remediation is complete. scope: in_scope: - www.boxabl.com (the BOXABL marketing site) - Any publicly exposed infrastructure element supporting BOXABL product or business operations out_of_scope: - Third-party business applications leveraged by BOXABL - Non-production environments, unless the vulnerability directly impacts production excluded_classes: - Configuration/best-practice findings (SPF/DMARC, CORS, security headers, weak TLS ciphers) - Denial of service - Information disclosure such as file paths, absent sensitive-data impact - Clickjacking - Email and account policy issues (reset method, password complexity) - Theoretical or self-XSS without demonstrated exploitability excluded_note: >- The excluded classes are in scope only where the implementation results in data leakage or account takeover. submission_preferences: - Written in English where possible - Include proof-of-concept code to aid triage - Include identification method, suggested impact rating and suggested remediation - More than raw automated scanner output - State any public-disclosure intentions or timelines evidence: - {source: 'well-known/boxabl-security.txt', kind: security.txt, field: Contact} - {source: 'https://gcdn.boxabl.com/documents/bugbounty/Boxabl%20Policy.pdf', kind: disclosure-policy, http_status: 200, content_type: application/pdf} probes: - {url: 'https://www.boxabl.com/.well-known/security.txt', status: 200} - {url: 'https://gcdn.boxabl.com/documents/bugbounty/Boxabl%20Policy.pdf', status: 200} - {url: 'https://www.boxabl.com/security', status: 404} - {url: 'https://trust.boxabl.com/', status: 0, note: host does not resolve} - {url: 'https://security.boxabl.com/', status: 0, note: host does not resolve} x-evidence: fetched: '2026-07-31' url: https://www.boxabl.com/.well-known/security.txt http_status: 200 content_type: text/plain; charset=utf-8