generated: '2026-09-07' method: searched source: >- https://www.checkpoint.com/vulnerability-disclosure-policy/ (HTTP 200, 105,524 bytes, title "Vulnerability Disclosure Policy - Check Point Software") and https://hackerone.com/checkpointsw (HTTP 200), both fetched 2026-09-07. provider: Dome9 providerId: dome9 scope_note: >- Dome9 has been Check Point CloudGuard since the 2018 acquisition and runs no separate security program of its own. The disclosure program below is Check Point's, and it is the one that covers this API surface. published: true policy_url: https://www.checkpoint.com/vulnerability-disclosure-policy/ contact: email: security-alert@checkpoint.com note: >- Check Point directs product vulnerability reports to security-alert@checkpoint.com, and asks researchers to contact that address before starting research if scope is unclear. bug_bounty: platform: hackerone url: https://hackerone.com/checkpointsw handle: checkpointsw verified: probed http_status: 200 bounty_offered: unknown note: >- The HackerOne page for Check Point Software Technologies resolves, but the program detail loads client-side and could not be read anonymously, so whether it pays bounties or is disclosure-only is NOT recorded here rather than guessed. policy_elements: safe_harbour: stated coordinated_disclosure_window: stated scope_defined: true note: >- The policy sets out covered systems, the research types in scope, the report submission process and a required waiting period before public disclosure. Exact day counts are not transcribed here because the page could not be re-fetched for verbatim quotation on a second pass. security_txt: served: false detail: >- No /.well-known/security.txt on api.dome9.com (404), the docs host (404) or www.checkpoint.com (404). The disclosure policy exists but is not machine-discoverable — a crawler following RFC 9116 finds nothing. cross_ref: well-known/dome9-well-known.yml evidence: - url: https://www.checkpoint.com/vulnerability-disclosure-policy/ status: 200 - url: https://hackerone.com/checkpointsw status: 200 - url: https://api.dome9.com/.well-known/security.txt status: 404 - url: https://www.checkpoint.com/.well-known/security.txt status: 404