generated: '2026-08-14' method: searched source: https://www.crossbeam.com/legal/responsible-disclosure docs: - https://www.crossbeam.com/legal/responsible-disclosure - https://www.crossbeam.com/what-is-crossbeam/security - https://www.crossbeam.com/legal/security-policy policy: - https://www.crossbeam.com/legal/responsible-disclosure contact: - security@crossbeam.com bug_bounty: program: false platform: null note: >- Crossbeam states plainly that it does not offer a public bug bounty. Disclosure is coordinated by email only — no HackerOne, Bugcrowd or Intigriti listing was found. scope: in_scope_systems: - www.crossbeam.com - app.crossbeam.com - api.crossbeam.com - partnerbase.com researcher_rules: - Do not conduct activity that could impact production systems or disclose personal or confidential data. - No denial-of-service testing. - No social engineering of Crossbeam employees or customers. reporting: >- Send findings to security@crossbeam.com with enough detail to reproduce and verify. assurance: penetration_testing: >- An external security firm conducts quarterly penetration tests of Crossbeam's systems; reports are available to customers on request under NDA. soc2_type_ii: true security_txt: served: false note: >- No /.well-known/security.txt is served on any Crossbeam-controlled host. The 200 at status.crossbeam.com/.well-known/security.txt is Atlassian's Statuspage vendor document (Canonical https://www.atlassian.com/.well-known/security.txt) and is not credited to Crossbeam. Publishing an RFC 9116 security.txt on www.crossbeam.com pointing at the existing responsible-disclosure page would be a one-file fix. evidence: - {source: https://www.crossbeam.com/legal/responsible-disclosure, http_status: 200, kind: disclosure-policy} - {source: https://www.crossbeam.com/what-is-crossbeam/security, http_status: 200, kind: security-page, contact: security@crossbeam.com} - {source: https://www.crossbeam.com/legal/security-policy, http_status: 200, kind: security-policy} - {source: https://status.crossbeam.com/.well-known/security.txt, http_status: 200, kind: third-party-vendor, credited: false} checked: '2026-08-14'