generated: '2026-08-14' method: searched source: https://flockjay.com/product/security (fetched 2026-08-14, HTTP 200) name: Flockjay vulnerability disclosure description: >- Flockjay publishes a named security contact and explicitly invites reports of potential security issues, on a public page that requires no form and no login. It does not publish a security.txt, a formal disclosure policy, safe-harbour terms, a response SLA for reports, or a bug bounty. program_published: true contact_published: true contact: email: security@flockjay.com page: https://flockjay.com/product/security quote: >- "If you have any questions, comments, or concerns or wish to report a potential security issue, please contact security@flockjay.com" security_txt: published: false probed: - {url: 'https://flockjay.com/.well-known/security.txt', status: 404} - {url: 'https://flockjay.com/security.txt', status: 404} - {url: 'https://api.flockjay.com/.well-known/security.txt', status: 404} note: >- The contact exists but is not machine-discoverable. Publishing the same address in an RFC 9116 security.txt is a five-minute change that would make it findable by automated tooling. policy_published: false safe_harbour: false disclosure_sla: null bug_bounty: program: false platform: null checked: - hackerone - bugcrowd - intigriti note: No bug bounty or coordinated-disclosure program was found on any platform. security_program: page: https://flockjay.com/product/security last_updated_on_page: '2025-02-10' controls_listed: organizational: - Information Security Program - Third-Party Audits - Third-Party Penetration Testing - Roles and Responsibilities - Security Awareness Training - Confidentiality - Background Checks cloud: - Cloud Infrastructure Security - Data Hosting Security - Encryption at Rest - Encryption in Transit - Vulnerability Scanning - Logging and Monitoring - Business Continuity and Disaster Recovery - Incident Response access: - Permissions and Authentication - Least Privilege Access Control - Quarterly Access Reviews - Password Requirements - Password Managers vendor: - Annual Risk Assessments - Vendor Risk Management note: >- Control HEADINGS only. The page names each control but the detail sits in a "Comprehensive Security Overview" document gated behind a lead-capture form (first name, last name, email, phone, company), so the substance is not publicly readable. evidence: - url: https://flockjay.com/product/security status: 200 - url: https://flockjay.com/.well-known/security.txt status: 404 - url: https://api.flockjay.com/.well-known/security.txt status: 404 related: trust_center: security/flockjay-trust-center.yml domain_security: security/flockjay-domain-security.yml