generated: '2026-09-07' method: searched probe: true source: https://trust.arcgis.com/en/security-concern/ note: >- Esri runs a Product Security Incident Response Team (PSIRT) with a published responsible- disclosure process and a public PGP key. Reports are filed through a categorised form on the ArcGIS Trust Center rather than a bug-bounty platform; no HackerOne/Bugcrowd/Intigriti program was found. The automated probe (probe-security-programs.py) found nothing because Esri serves no /.well-known/security.txt on any host and the disclosure page lives on trust.arcgis.com rather than a /security path on esri.com — this file is the searched upgrade over that miss. policy: - https://trust.arcgis.com/en/security-concern/ contact: [] contact_note: >- Esri publishes a web submission form, not an email address, on the security-concern page. No security@ address is advertised there, so none is recorded. pgp_key: https://trust.arcgis.com/en/security-concern/esri-psirt-pgp.asc program: team: Esri PSIRT (Product Security Incident Response Team) bug_bounty: false safe_harbor: true safe_harbor_text: >- "Esri will not bring a lawsuit or begin law enforcement investigation of you if this policy is followed." commitments: - Timely response acknowledging receipt of the report - Notification to the reporter when the vulnerability is fixed report_categories: - ArcGIS Software Vulnerability - "Privacy Issue: ArcGIS Software Product" - "Privacy Issue: Esri Corporate" - "Privacy Issue: Unsafe Site or URL" - Other security, privacy or compliance concerns advisories: https://www.esri.com/arcgis-blog/products/trust-arcgis/administration/ advisories_note: Esri publishes periodic ArcGIS Security Bulletins on the ArcGIS Blog. evidence: - {source: https://trust.arcgis.com/en/security-concern/, kind: disclosure-policy, http_status: 200, fetched: '2026-09-07'} - {source: https://trust.arcgis.com/en/, kind: trust-center, http_status: 200, fetched: '2026-09-07'} - {source: well-known/esri-well-known.yml, kind: security.txt, result: 'absent — 404 on every host probed'}