generated: '2026-09-07' method: searched source: https://www.cvent.com/en/event-management-software/vulnerability-disclosure-program description: >- Social Tables is a Cvent product and has no vulnerability-disclosure surface of its own — no /.well-known/security.txt is served on any socialtables.com host (see well-known/cvent-social-tables-well-known.yml, 5 hosts, all 404). Coordinated disclosure for Social Tables runs through the Cvent Vulnerability Disclosure Program, which is public, first-party to the owning company, and linked from the Cvent Trust Center. program: present: true name: Cvent Vulnerability Disclosure Program url: https://www.cvent.com/en/event-management-software/vulnerability-disclosure-program http_status: 200 operator: Cvent, Inc. (owner of Social Tables) platform: self-hosted (no HackerOne / Bugcrowd / Intigriti program found) contact: security@cvent.com contact_source: >- Published on the Cvent Trust Center — "Have a question that isn't covered here? Reach out directly at security@cvent.com." (https://trust.cvent.com/, read 2026-09-07) scope_note: >- The program page states it covers "a potential security vulnerability in a Cvent product". Social Tables / Cvent Event Diagramming is a Cvent product, so it falls inside that scope; the page does not enumerate hosts, so this record does not assert a per-host scope list. bug_bounty: >- The Cvent Trust Center summary asserts "Has a bug bounty or vulnerability disclosure program". No paid bounty terms, reward table, or safe-harbor legal text was found on the public program page. security_txt: served: false hosts_probed: - socialtables.com - www.socialtables.com - api.socialtables.com - developer.socialtables.com - auth.socialtables.com status: 404 note: >- RFC 9116 security.txt is the machine-readable half of this; it is absent everywhere, so an agent or scanner cannot find the disclosure channel without reading marketing pages. evidence: - url: https://www.cvent.com/en/event-management-software/vulnerability-disclosure-program status: 200 finding: Vulnerability Disclosure Program page, first-party to Cvent. - url: https://trust.cvent.com/ status: 200 finding: 'Trust Center quick link "Report a Vulnerability" plus security@cvent.com contact.' - url: https://www.socialtables.com/.well-known/security.txt status: 404 finding: No security.txt on the product domain.