generated: '2026-07-19' method: searched source: https://github.com/fleetdm/fleet/blob/main/SECURITY.md probe: false policy: - https://github.com/fleetdm/fleet/blob/main/SECURITY.md - https://bugbop.com/programs/b5f2f20e-fe4d-466b-a474-6db65b4d2bb3 contact: - security@fleetdm.com bug_bounty: platform: Bugbop type: vulnerability-disclosure-program url: https://bugbop.com/programs/b5f2f20e-fe4d-466b-a474-6db65b4d2bb3 pgp: fingerprint: '82F2 AF19 547E 462A 4605 D538 01B2 575E 4676 6EBE' key: https://keys.openpgp.org/vks/v1/by-fingerprint/82F2AF19547E462A4605D53801B2575E46766EBE scope: in: - Fleet product source code (github.com/fleetdm/fleet) - Fleet REST API documentation (fleetdm.com/docs/rest-api/rest-api) out: - Marketing pages, blogs, and landing pages on fleetdm.com - Third-party hosted services (unless they directly impact an in-scope asset) - Physical offices and infrastructure - Employee social media accounts sla: acknowledgement: typically within 1 business day patch: usually within 5 business days (severity/timing dependent) evidence: - {source: 'https://github.com/fleetdm/fleet/blob/main/SECURITY.md', kind: security-policy} - {source: 'https://bugbop.com/programs/b5f2f20e-fe4d-466b-a474-6db65b4d2bb3', kind: vdp}