generated: '2026-08-27' method: probed source: >- live probes of /.well-known/security.txt on 6 Everbridge hosts, plus a search of everbridge.com legal/security pages, the SafeBase trust center, and HackerOne/Bugcrowd/Intigriti provider: Everbridge providerId: everbridge published: false description: >- FINDING — Everbridge publishes no public vulnerability disclosure programme. No host serves /.well-known/security.txt, no responsible-disclosure or coordinated-disclosure page exists on everbridge.com, and no bug bounty programme was found on HackerOne, Bugcrowd or Intigriti. The only disclosure contact API Evangelist could locate is stated inside a customer-only support article that 302s to a Zendesk login, so it is not a publicly reachable disclosure channel and is not asserted here as one. security_txt: served: false hosts_probed: - host: www.everbridge.com status: 404 - host: everbridge.com status: 301 - host: api.everbridge.net status: 404 - host: developers.everbridge.net status: 302 - host: api.snapcomms.com status: 404 - host: www.snapcomms.com status: 404 checked: '2026-08-27' bug_bounty: program: null platforms_checked: - HackerOne - Bugcrowd - Intigriti found: false disclosure_page: url: null found: false gated_reference: claim: >- A customer-only Everbridge support article ("EBS: Everbridge Suite Security & Privacy Compliance") is reported to state that responsible security disclosures may be sent to security@everbridge.com. url: https://supportcenter.everbridge.com/hc/en-us/articles/19141654075163-EBS-Everbridge-Suite-Security-Privacy-Compliance status: 302 redirect_to: everbridgesupport.zendesk.com/access (customer login) verified: false note: >- Not independently verified because the article requires authentication. Recorded as a lead, not as a published disclosure channel. If Everbridge moved this one sentence to a public page and served a /.well-known/security.txt pointing at it, this artifact would flip to published with no other change. public_security_contact: email: EverbridgeSecureDocuments@everbridge.com purpose: trust-center document access, not vulnerability reporting source: https://trust.everbridge.com/ remediation: - Publish /.well-known/security.txt (RFC 9116) on www.everbridge.com and api.everbridge.net with Contact and Policy fields. - Move the responsible-disclosure statement out of the authenticated support centre onto a public page. maintainers: - FN: Kin Lane email: kin@apievangelist.com