generated: '2026-08-19' method: probed source: https://www.cisco.com/.well-known/security.txt name: Cisco Product Security Incident Response Team (PSIRT) published: true program: type: coordinated-disclosure operator: Cisco PSIRT scope: >- All Cisco products and cloud services, which includes the Cisco Crosswork portfolio (Network Controller, Data Gateway, Zero Touch Provisioning, Optimization Engine, Workflow Manager). bug_bounty: false bug_bounty_note: >- No HackerOne, Bugcrowd or Intigriti program was found for Cisco Crosswork. Cisco runs coordinated disclosure through PSIRT rather than a public bounty platform. contact: email: psirt@cisco.com source: security.txt Contact field pgp_key: https://cscrdr.cloudapps.cisco.com/cscrdr/security/center/files/Cisco_PSIRT_PGP_Public_Key.asc pgp_fingerprint: 081e38f3eb110265a214514124b3ec61e4205802 policy: url: https://sec.cloudapps.cisco.com/security/center/resources/security_vulnerability_policy.html source: security.txt Policy field advisories: machine_readable: true format: CSAF 2.0 role: csaf_trusted_provider provider_metadata: https://www.cisco.com/.well-known/csaf/provider-metadata.json directory: https://www.cisco.com/.well-known/csaf/ note: >- Cisco is a CSAF trusted provider and publishes its security advisories as machine-readable CSAF documents. This is a materially stronger disclosure posture than a contact address alone: an agent can consume the advisory feed without scraping. security_txt: served: true url: https://www.cisco.com/.well-known/security.txt file: well-known/cisco-crosswork-security.txt signed: true signature: PGP clear-signed expires: '2027-01-01T00:00:00.000Z' x-evidence: - url: https://www.cisco.com/.well-known/security.txt http_status: 200 content_type: text/plain - url: https://www.cisco.com/.well-known/csaf/provider-metadata.json http_status: 200 content_type: application/json - url: https://developer.cisco.com/.well-known/security.txt http_status: 404 note: The Crosswork documentation host does not serve its own security.txt; the corporate host does. checked: '2026-08-19'