generated: '2026-09-05' method: searched probe: true source: https://hackerone.com/caterpillar note: >- Caterpillar runs a coordinated vulnerability disclosure program. The HackerOne program page is live (HTTP 200, fetched 2026-09-05) and Caterpillar also publishes a first-party reporting page on cat.com. The cat.com page could not be read directly — the corporate Akamai edge returns 403 to every non-browser client, including a control path that cannot exist — so it is recorded with the status actually observed rather than asserted as read. No RFC 9116 /.well-known/security.txt is served on any Caterpillar host. policy: - https://hackerone.com/caterpillar - https://www.cat.com/en_US/support/maintenance/c/report-potential-information-security-vulnerabilities.html contact: [] security_txt: false bug_bounty: false disclosure_type: vulnerability-disclosure-program platforms: - name: HackerOne url: https://hackerone.com/caterpillar http_status: 200 program_terms: pgp_encryption_requested: true acknowledgement_target: within 72 hours triage_response_target: within five business days public_disclosure_allowed: false note: >- Terms as described by Caterpillar's published program summary. Recorded as reported by the program pages; the HackerOne page renders client-side and could not be parsed field by field. evidence: - source: https://hackerone.com/caterpillar kind: vdp-platform-page http_status: 200 - source: https://www.cat.com/en_US/support/maintenance/c/report-potential-information-security-vulnerabilities.html kind: first-party-disclosure-page http_status: 403 note: Akamai edge policy blocks non-browser clients; the page is indexed and titled "Report Potential Security Vulnerabilities | Cat | Caterpillar". - source: /.well-known/security.txt on caterpillar.com, www.caterpillar.com, cat.com, www.cat.com, digital.cat.com, api.cat.com, services.cat.com, fedlogin.cat.com kind: security-txt-probe result: not served