generated: '2026-09-05' method: searched source: https://capsulecrm.com/security/ description: >- Capsule publishes a security contact for reporting sensitive issues, but no formal vulnerability disclosure policy, safe-harbour statement or bug bounty. security_txt: served: false probed_hosts: - capsulecrm.com - www.capsulecrm.com - api.capsulecrm.com - developer.capsulecrm.com status: 404 probed: '2026-09-05' contact: email: support+sensitive@capsulecrm.com channel: email source: https://capsulecrm.com/security/ statement: >- Capsule directs urgent or sensitive security concerns to support+sensitive@capsulecrm.com. policy: published: false url: null safe_harbour: false disclosure_timeline: null note: >- No coordinated-disclosure policy document, no response-time commitment and no researcher safe-harbour language was found on capsulecrm.com. bug_bounty: program: false platform: null note: No HackerOne, Bugcrowd or Intigriti program was found. penetration_testing: stated: true statement: >- "We work with certified independent specialists on a regular basis to undertake systems penetration testing." reports_published: false maintainers: - FN: Kin Lane email: kin@apievangelist.com