generated: '2026-08-04' method: searched probe: true source: https://docs.dataloop.ai/docs/data-privacy-security policy: - https://dataloop.ai/security/ - https://docs.dataloop.ai/docs/data-privacy-security contact: - security@dataloop.ai security_txt: false bug_bounty: advertised: true platform: unnamed quote: >- "We maintain a strong security culture by offering a bug bounty program, incentivizing individuals to report security exploits and vulnerabilities." url: null note: >- Dataloop states it operates a bug bounty program but names no platform (no HackerOne / Bugcrowd / Intigriti program page was found) and publishes no submission URL or program rules. penetration_testing: performed: true cadence: quarterly vendor: external (unnamed) report_available: true report_access: >- Pentest Report is listed on the SafeBase trust center under access-controlled documents; customers can also request quarterly security reports through their account manager. source: https://trust.dataloop.ai/ vulnerability_testing: performed: true driver: SOC 2 requirements source: https://docs.dataloop.ai/docs/data-privacy-security evidence: - source: https://dataloop.ai/security/ kind: security-page http_status: 200 fetched: '2026-08-04' keywords: [bug bounty, vulnerability, penetration] - source: https://docs.dataloop.ai/docs/data-privacy-security kind: docs http_status: 200 fetched: '2026-08-04' keywords: [bug bounty, vulnerability tests, security reports] - source: https://trust.dataloop.ai/ kind: trust-center http_status: 200 fetched: '2026-08-04' keywords: [security@dataloop.ai, pentest report] gap: summary: >- A bug bounty program and a security contact are advertised, but there is no machine-discoverable entry point — no /.well-known/security.txt (404 on dataloop.ai), no named bounty platform, and no responsible-disclosure page with scope, safe-harbor, or response targets. A researcher has to infer security@dataloop.ai from the trust center.