# Comcast — vulnerability disclosure program # # probe-security-programs.py returned vdp=none for this slug because Comcast # serves no /.well-known/security.txt on any host in this record (probed # 2026-09-05 — see well-known/comcast-well-known.yml). The program nevertheless # exists and is substantial; it is simply not discoverable at the RFC 9116 path. # Upgraded to method: searched from the provider's own published policy page. generated: '2026-09-05' method: searched source: https://www.xfinity.com/vulnerabilityreport (HTTP 200, fetched 2026-09-05) provider: Comcast providerId: comcast published: true policy_url: https://www.xfinity.com/vulnerabilityreport policy_url_status: 200 security_txt: false security_txt_note: >- No /.well-known/security.txt served on comcast.com, www.comcast.com, www.xfinity.com, developers.xfinity.com, docs.developer.comcast.com, developer.comcast.com or either codebig2.net API host. This is a real discoverability gap: a machine looking for the program at the standard path will not find it, and www.comcast.com additionally answers 406 to crawlers. contact: email: securitydefectreporting@comcast.com pgp: true web_form: https://www.xfinity.com/vulnerabilityreport form_platform: Bugcrowd platforms: - platform: Bugcrowd programs: - name: Comcast Xfinity Vulnerability Disclosure Program url: https://bugcrowd.com/engagements/comcastvdp status: 200 - name: Xfinity Home & xFi url: https://bugcrowd.com/engagements/xfinity-home status: 200 - name: Comcast MBB url: https://bugcrowd.com/engagements/comcast-mbb rewards: offered: true guaranteed: false statement: >- "not all submissions are eligible for a reward; eligibility depends on the merit, quality, and impact of the findings." scope_definition: >- Comcast defines a security vulnerability as "an unintended weakness or exposure that could be used to compromise the integrity, availability or confidentiality of our products and services." Reports are accepted from independent researchers, industry partners, vendors, customers and consultants. principles: - Trust — confidentiality is maintained in exchanges with researchers. - Respect — researchers are asked to avoid privacy violations, degradation of user experience, disruption of production systems and destruction of data. - Transparency — researchers provide the technical detail needed to validate a report. - Common Good — no public disclosure of unverified vulnerabilities before validation. related: research_program: https://corporate.comcast.com/cybersecurity/ccs-research research_program_status: 200 covers_developer_platform: unknown covers_developer_platform_note: >- The policy is written for Comcast/Xfinity products and services generally. It does not name the Firebolt developer platform, docs.developer.comcast.com or the codebig2.net API hosts in scope, and the Bugcrowd scopes were not readable anonymously. No claim is made either way. maintainers: - FN: Kin Lane email: kin@apievangelist.com