generated: '2026-08-12' method: searched source: https://trust.esentire.com/api/trustpage/public/v1/ name: eSentire security disclosure description: >- eSentire publishes a named security contact but not a vulnerability disclosure policy. The contact is genuine and provider-published — security@esentire.com, attributed on eSentire's own trust page to the "Office of the CISO / Governance Risk and Compliance Team". That is the entire published surface. There is no disclosure policy page, no safe-harbour statement, no reporting SLA, no PGP key, no RFC 9116 security.txt on any eSentire host, and no bug bounty program on HackerOne, Bugcrowd or Intigriti. For an MDR vendor whose own research unit publishes security advisories about other people's software, the absence of an inbound disclosure policy is a notable asymmetry. contact: email: security@esentire.com attributed_to: Office of the CISO — Governance Risk and Compliance Team published_at: https://trust.esentire.com/ verified: true policy: published: false url: null safe_harbor: false sla: null pgp_key: null security_txt: present: false hosts_probed: - host: www.esentire.com path: /.well-known/security.txt status: 404 - host: www.esentire.com path: /security.txt status: 404 - host: api.esentire.com path: /.well-known/security.txt status: 403 - host: atlas.esentire.com path: /.well-known/security.txt status: 200 note: SPA HTML shell, not a security.txt. Rejected. bug_bounty: present: false programs_probed: - url: https://hackerone.com/esentire status: 404 - url: https://bugcrowd.com/esentire status: 404 incident_hotline: phone: 1-866-579-2200 purpose: >- eSentire's 24/7 emergency line for organizations experiencing a breach. This is a customer/prospect incident-response intake, NOT a vulnerability-report channel for eSentire's own products. Recorded to keep the two from being conflated. published_at: https://www.esentire.com/ related_publications: security_advisories: https://www.esentire.com/resources/security-advisories note: >- Outbound advisories from eSentire's Threat Response Unit (TRU) about third-party vulnerabilities. Not a disclosure channel for reporting issues in eSentire. gaps: - No vulnerability disclosure policy is published anywhere on eSentire's public surface. - No security.txt is served, so the contact is not machine-discoverable — a researcher has to render a JavaScript trust page to find it. - No safe-harbour language, so a good-faith researcher has no published legal assurance. - No bug bounty or coordinated-disclosure program. x-evidence: fetched: '2026-08-12' urls: - url: https://trust.esentire.com/api/trustpage/public/v1/ status: 200 note: Contains contactEmail security@esentire.com, contactFullName "Office of the CISO". - url: https://www.esentire.com/.well-known/security.txt status: 404 - url: https://www.esentire.com/responsible-disclosure status: 404 - url: https://www.esentire.com/vulnerability-disclosure status: 404 - url: https://hackerone.com/esentire status: 404 - url: https://bugcrowd.com/esentire status: 404