generated: '2026-09-12' method: searched source: https://www.guidewire.com/contact-us/vulnerability-disclosure-policy/ provider: guidewire providerId: guidewire published: true http_status: 200 probed: '2026-09-12' policy_url: https://www.guidewire.com/contact-us/vulnerability-disclosure-policy/ contact: email: psirt@guidewire.com form: null note: PSIRT (Product Security Incident Response Team) mailbox. No web form is published. scope: Security vulnerabilities discovered in Guidewire products and services. required_report_contents: - title - description - severity, scored with CVSS 3.0 - impact - location / affected component - recommended remediation - proof of concept bug_bounty: offered: false evidence: >- "At this time, Guidewire does not offer a Bug Bounty Program or compensation to researchers for vulnerability reports." platforms_checked: [HackerOne, Bugcrowd, Intigriti] platforms_found: [] safe_harbor: published: false note: >- No explicit safe-harbor clause protecting good-faith research from legal action. The policy instead requires the reporter to treat the submission as Guidewire Confidential Information: "By engaging or participating in and/or submitting a security vulnerability to Guidewire, you agree to treat that information as the Confidential Information of Guidewire." response_commitments: acknowledgement_sla: null remediation_sla: null note: >- Guidewire commits to working with the reporter to verify the issue and to notifying affected customers where remediation is required. No timeline is published. security_txt: published: false note: >- No RFC 9116 /.well-known/security.txt is served on guidewire.com, www.guidewire.com or docs.guidewire.com. The only security.txt reachable on a guidewire.com host is on status.guidewire.com and it belongs to Atlassian (Statuspage), not Guidewire — see well-known/guidewire-well-known.yml. Publishing a security.txt pointing at psirt@guidewire.com and the policy URL above would be a one-file fix. related: trust_center: security/guidewire-trust-center.yml security_docs: https://docs.guidewire.com/security/