generated: '2026-08-13' method: searched probe: true source: https://www.frontify.com/en/security/ url: https://www.frontify.com/en/security/ description: >- Frontify runs a named vulnerability-disclosure program with two intake paths — an official BugCrowd bug bounty and a direct security mailbox. The page states it in Frontify's own words: "The Frontify Bug Bounty — Report security issues through our official BugCrowd bounty program or contact our security team at security@frontify.com." The page's "Report vulnerability" button targets mailto:security@frontify.com. policy: - https://www.frontify.com/en/security/ contact: - security@frontify.com bug_bounty: platform: BugCrowd program_url: null program_url_note: >- Frontify names BugCrowd as its official bounty platform but does not link a public program page from the security page, and no public BugCrowd program page for Frontify was found (bugcrowd.com/frontify and bugcrowd.com/engagements/frontify both returned 404). The program is therefore either private/invite-only or listed under a different handle. Recorded as named-but-unlinked rather than asserted as public. security_txt: served: false note: >- No /.well-known/security.txt on any Frontify host — www.frontify.com 404s with an "Invalid .well-known request" stub. Publishing an RFC 9116 security.txt pointing at this page and mailbox is a one-file fix. See well-known/frontify-well-known.yml. related_practices: source: https://www.frontify.com/en/security/ claims: - Development process follows OWASP guidelines with code reviews, pair programming and automated security tests. - Incident management and reporting process spanning internal operations and customer-facing services. - Customer notification within 48 hours of a security breach affecting customer data. - Nightly backups of files, databases, configuration and servers; disaster-recovery procedures tested at least annually. evidence: - source: https://www.frontify.com/en/security/ http_status: 200 kind: security-page matched: [BugCrowd, "security@frontify.com", bug bounty] checked: '2026-08-13' - source: https://bugcrowd.com/frontify http_status: 404 kind: bounty-program-lookup checked: '2026-08-13' - source: https://trust.frontify.com/ http_status: 200 kind: trust-center matched: [responsible disclosure] checked: '2026-08-13' note: >- The mechanical probe (0-working/probe-security-programs.py) reported vdp=none for this provider because Frontify's disclosure surface is at /en/security/ rather than any of the conventional /security, /responsible-disclosure or /.well-known/security.txt paths the probe checks. This file is the searched upgrade over that miss.