generated: '2026-06-20' method: searched probe: true source: https://www.elastic.co/community/security policy: - https://hackerone.com/elastic - https://www.elastic.co/community/security - https://www.elastic.co/product-security contact: - security@elastic.co bug_bounty: platform: HackerOne url: https://hackerone.com/elastic scope: >- Elastic products, the Elastic Cloud Service, and the elastic.co website. A separate bounty chapter covers Elastic Security detection rules (SIEM) and endpoint rules (EDR). disclosure: model: Coordinated Vulnerability Disclosure advisories: Elastic Security Advisories (ESA) + CVE program notes: >- Email reports to security@elastic.co are accepted but are NOT eligible for a bounty; use the HackerOne program for rewards. evidence: - source: https://hackerone.com/elastic kind: bug-bounty - source: https://www.elastic.co/product-security kind: disclosure-page - source: https://www.elastic.co/community/security kind: disclosure-page