generated: '2026-08-13' method: searched probe: true source: https://www.smartsheet.com/.well-known/security.txt url: https://www.smartsheet.com/legal/bugbounty policy: - https://www.smartsheet.com/legal/bugbounty contact: - security@smartsheet.com - https://www.smartsheet.com/legal/bugbounty security_txt: served_on_api_host: false host: www.smartsheet.com file: well-known/brandfolder-security.txt canonical: https://www.smartsheet.com/.well-known/security.txt expires: '2026-07-01T04:00:00.000Z' expired_at_probe: true preferred_languages: en attribution_note: > Brandfolder does not run its own disclosure program and serves no security.txt on brandfolder.com (404). The applicable program is the parent company's: Brandfolder has been a Smartsheet company since August 2020, and brandfolder.com's own CAA record carries `0 iodef "mailto:security@smartsheet.com"` - the provider's own DNS naming Smartsheet security as the reporting channel for this domain. That is why the Smartsheet researcher portal is recorded here rather than treated as a different company's program. evidence: - source: https://www.smartsheet.com/.well-known/security.txt kind: security.txt status: 200 - source: https://www.smartsheet.com/legal/bugbounty kind: researcher-portal status: 200 - source: https://brandfolder.com/.well-known/security.txt kind: security.txt status: 404 - source: brandfolder.com CAA record kind: dns value: '0 iodef "mailto:security@smartsheet.com"' gaps: - The published security.txt Expires field is 2026-07-01 - the document was expired when probed on 2026-08-13. - No security.txt on the API host (brandfolder.com) or the docs host (developers.smartsheet.com).