generated: '2026-08-29' method: searched probe: true source: https://firehydrant.com/security/ policy: - https://firehydrant.com/security/ contact: - security@firehydrant.io response_target: 72 hours bug_bounty: null bug_bounty_note: >- No HackerOne, Bugcrowd or Intigriti program is published. Disclosure is direct to security@firehydrant.io. submission_requirements: - Description of discovery - URL(s) affected - Steps for reproduction - Source IP address used during discovery - Your name and company (if applicable) - Preferred contact information (phone number, email address) security_txt: false security_txt_note: >- No /.well-known/security.txt is served on any FireHydrant host — see well-known/firehydrant-well-known.yml. The disclosure program exists only as an HTML section on the marketing security page, which is the single easiest gap for FireHydrant to close. evidence: - source: https://firehydrant.com/security/ http_status: 200 kind: disclosure-page quote: >- "We take security vulnerability reports seriously. FireHydrant aims to respond to all reports within 72 hours." - source: https://firehydrant.com/.well-known/security.txt http_status: 404 kind: security.txt