generated: '2026-08-13' method: searched source: https://www.zoominfo.com/legal/security-overview source_status: 200 scope_note: >- Chorus.ai publishes no independent disclosure program. Chorus.ai was acquired by ZoomInfo in 2021 and chorus.ai now redirects to zoominfo.com/products/chorus, so ZoomInfo's program is the governing one for the Chorus service. Recorded at the parent level and labelled as such. program: published: true holder: ZoomInfo type: bug bounty name: ZoomInfo Bug Bounty Program url: https://www.zoominfo.com/trust-center/bug-bounty-program url_status: 403 url_note: >- The bug-bounty page itself answers 403 to a scripted request (edge bot protection); it is linked and described in prose from https://www.zoominfo.com/legal/security-overview, which returns 200 and is the evidence recorded here. statement: >- "ZoomInfo accepts reporting of flaws in our perimeter security by ethical hackers that report on such weaknesses and vulnerabilities. You can review our bug bounty program rules and submission page..." platform: not stated on the public page safe_harbor: not stated on the public page bounty_offered: not stated on the public page contact: email: security@zoominfo.com instruction: >- "If you become aware of an actual or potential security issue, such as receiving a phishing email purporting to be from ZoomInfo, bugs, or any other security concern, please let us know by contacting us at security@zoominfo.com" source: https://www.zoominfo.com/legal/security-overview security_txt: published: false probes: - url: https://chorus.ai/.well-known/security.txt status: 403 - url: https://www.chorus.ai/.well-known/security.txt status: 404 - url: https://www.zoominfo.com/.well-known/security.txt status: 403 note: >- No RFC 9116 security.txt is served on any Chorus host. The security contact exists only in prose on a marketing-site legal page, so an automated scanner cannot discover it. remediation_posture: scanning: >- "Networks, systems, and application aspects are regularly scanned. Any critical vulnerabilities are addressed upon discovery." process: >- "ZoomInfo takes a proactive approach to security and quickly addresses risks. When a weakness is found, a risk review is performed." source: https://www.zoominfo.com/legal/security-overview probed: '2026-08-13' cross_links: trust_center: security/chorus-ai-trust-center.yml well_known: well-known/chorus-ai-well-known.yml conformance: conformance/chorus-ai-conformance.yml