generated: '2026-08-29' method: searched source: https://www.elastic.co/product-security provider: Elastic Observability providerId: elastic-observability published: true policy_url: https://www.elastic.co/product-security contact: security@elastic.co pgp_fingerprint: 1224 D1A5 72A7 3755 B61A 377B 14D6 5EE0 D2AE 61D2 security_txt: served: true host: api.elastic-cloud.com url: https://api.elastic-cloud.com/.well-known/security.txt probed: '2026-08-29' probe_status: 200 content_type: text/plain file: ../well-known/elastic-observability-security.txt fields: Contact: security@elastic.co Encryption: openpgp4fpr:1224D1A572A73755B61A377B14D65EE0D2AE61D2 Hiring: https://www.elastic.co/about/careers Policy: https://www.elastic.co/cloud/security note: >- www.elastic.co and elastic.co both 404 /.well-known/security.txt — only the API host serves it. The file carries no Expires field, which RFC 9116 requires. bug_bounty: offered: true platform: HackerOne url: https://hackerone.com/elastic probed: '2026-08-29' probe_status: 200 exclusivity: >- "If you wish to be considered for a bounty, you must submit your report exclusively through our official bug bounty program" — reports sent by email are not eligible for a bounty. disclosure: model: coordinated vulnerability disclosure embargo_request: >- Elastic asks researchers not to "post or share any information about potential vulnerabilities in any public forum until we have researched and responded to the issue via our official channels." advisories: Elastic Security Advisory (ESA) advisories_url: https://discuss.elastic.co/c/announcements/security-announcements cna: true cna_note: Elastic is an authorized CVE Numbering Authority and assigns its own CVE IDs. safe_harbor: published: false note: No explicit safe-harbour / legal-protection language appears in the policy. response_sla: published: false