generated: '2026-08-04' method: searched source: https://www.debtbook.com/vdp probe: true program: name: DebtBook Vulnerability Disclosure Program url: https://www.debtbook.com/vdp type: responsible-disclosure bug_bounty: false monetary_rewards: false platform: none intake: web form linked from the DebtBook security page (no third-party platform such as HackerOne, Bugcrowd or Intigriti is used) policy: - https://www.debtbook.com/vdp contact: - https://www.debtbook.com/security - hello@debtbook.com scope: in_scope: - app.debtbook.com - sources.debtbook.com - uat.debtbook.com out_of_scope: - the third-party Intercom messaging script embedded in the application requirements: - Researchers must include the token "(db_vdp)" in the HTTP User-Agent header so security testing traffic can be distinguished from real user traffic. - No unauthorized access, data exfiltration, or service disruption. safe_harbor: offered: true covers: - Computer Fraud and Abuse Act (CFAA) - Digital Millennium Copyright Act (DMCA) condition: good-faith research that follows the published program guidelines sla: first_response: 5 business days time_to_triage: 10 business days resolution: dependent on severity and complexity security_txt: published: false note: no /.well-known/security.txt is served on debtbook.com, www.debtbook.com or app.debtbook.com (RFC 9116 gap — the VDP exists but is not machine-discoverable) evidence: - source: https://www.debtbook.com/vdp kind: vulnerability-disclosure-policy http_status: 200 fetched: '2026-08-04' - source: https://www.debtbook.com/security kind: security-page http_status: 200 fetched: '2026-08-04' x-evidence: fetched: '2026-08-04' note: the mechanical probe (probe-security-programs.py) returned no hit because the policy lives at the non-standard path /vdp and the HubSpot-rendered /security page did not meet the keyword threshold; both pages were then fetched and read directly.