generated: '2026-09-17' method: searched source: https://dev.to/security + https://github.com/forem/forem/blob/main/SECURITY.md policy_url: https://dev.to/security http_status: 200 contact: email: security@dev.to type: email security_txt: served: false probed: https://dev.to/.well-known/security.txt status: 404 note: The policy is published as an HTML page only; RFC 9116 security.txt is not served on any host. bug_bounty: active: false platform: null statement: '"We regret to announce we will be suspending our bug bounty reward program effective immediately... While we are no longer able to offer monetary rewards at this time, we still highly value the security community’s input and encourage you to continue reporting any vulnerabilities you may discover."' note: Rewards suspended, reports still accepted. No timeline published for relaunch. recognition: hall_of_fame: true note: '"We remain committed to acknowledging significant contributions through our security hall of fame."' scope: out_of_scope_hosts: - jobs.dev.to (Recruitee) - status.dev.to (Atlassian) - shop.dev.to (Shopify) - docs.dev.to (Netlify) - storybook.dev.to (Netlify) note: Third-party-hosted subdomains are excluded; DEV names each vendor so a researcher can route the report. rules: - Do not test vulnerabilities in public or in ways that affect other community members. - Report similar issues or variations of one issue in a single report. repository_policy: url: https://github.com/forem/forem/blob/main/SECURITY.md statement: '"Please refer to https://dev.to/security if you would like to report a vulnerability."' note: A real, first-party, currently-maintained coordinated disclosure programme — reward-free but staffed and scoped.