generated: '2026-09-05' method: searched source: >- https://www.apple.com/.well-known/security.txt (200), https://security.apple.com (200), https://security.apple.com/bounty/guidelines/, https://developer.apple.com/security-bounty/ (200) program: Apple Security Bounty published: true security_txt: url: https://www.apple.com/.well-known/security.txt status: 200 file: ../well-known/cloudkit-security.txt contact: https://security.apple.com policy: https://security.apple.com/bounty/guidelines/ acknowledgments: - https://support.apple.com/HT201222 - https://support.apple.com/HT201536 expires: '2027-08-28T01:00:00.000Z' bounty: offered: true platform: self-hosted url: https://security.apple.com/bounty/ developer_page: https://developer.apple.com/security-bounty/ scope_note: >- Apple runs its own bounty rather than HackerOne/Bugcrowd/Intigriti. iCloud — the service CloudKit stores into — is inside the published Apple Security Bounty scope categories; CloudKit is not named as a separate program. reporting: channel: https://security.apple.com note: >- The only intake this pipeline verified is the Contact URL published in Apple's security.txt (https://security.apple.com, HTTP 200 on 2026-09-05). No email intake was probed, so none is recorded here. scope_caveat: >- This is Apple's corporate-wide disclosure program, reachable from the apple.com registrable domain that developer.apple.com and the CloudKit surfaces sit under. There is no CloudKit-specific disclosure page.