generated: '2026-09-07' method: searched source: https://www.cvent.com/en/event-management-software/vulnerability-disclosure-program (HTTP 200, fetched 2026-09-07); https://trust.cvent.com/ program: published: true name: Cvent Vulnerability Disclosure Program url: https://www.cvent.com/en/event-management-software/vulnerability-disclosure-program report_form: https://www.cvent.com/en/event-management-software/report-security-vulnerability contact_email: security@cvent.com contact_email_source: https://trust.cvent.com/ bug_bounty: false rewards: false platform: null safe_harbor: false safe_harbor_note: The policy contains no explicit safe-harbor clause; it requires reporters to keep the vulnerability confidential and not disclose publicly. response_commitment: Cvent Security acknowledges receipt of each reported vulnerability, investigates, and takes action for resolution. No response-time SLA is stated. out_of_scope: - Data modification - Unauthorized account access - DoS / DDoS testing - Spam - Third-party integrations - Malware distribution - Any illegal activity security_txt: served: false probed: - https://cvent.com/.well-known/security.txt - https://www.cvent.com/.well-known/security.txt - https://developers.cvent.com/.well-known/security.txt - https://api-platform.cvent.com/.well-known/security.txt status: 404 note: Cvent runs a disclosure program but publishes no RFC 9116 security.txt on any host, so an automated scanner finds nothing at the machine-readable path.