generated: '2026-08-13' method: searched probe: true source: https://hunter.io/security-policy policy: [https://hunter.io/security-policy] contact: [] contact_note: >- Hunter states it runs "an ongoing Bug Bounty Program, which allows independent security researchers to report security threats and vulnerabilities on an ongoing basis" but publishes no submission address, no bounty-platform link (no HackerOne/Bugcrowd/Intigriti page was found) and no security@ mailbox. A researcher reading the policy has no stated way to report. The only published mailboxes are privacy@hunter.io (privacy) and contact@hunter.io (support). bug_bounty: exists: true platform: null url: null evidence_quote: >- "Bounty Program - Hunter has an ongoing Bug Bounty Program, which allows independent security researchers to report security threats and vulnerabilities on an ongoing basis." security_txt: served: false probed: [https://hunter.io/.well-known/security.txt, https://api.hunter.io/.well-known/security.txt, https://hunter.io/security.txt] status: 404 program_controls: - Independent third-party penetration tests of new services. - Internal security reviews before deploying new services or code. - Regular third-party vulnerability scanning of infrastructure and systems. - Proactive evaluation and application of critical software patches. - Role-based access control on a least-privilege model. - Daily backups on Google Cloud, encrypted at rest with AES. evidence: - {source: https://hunter.io/security-policy, kind: security-policy, http_status: 200, keywords: [bug bounty, vulnerabilities, penetration tests, access controls]} - {source: https://hunter.io/.well-known/security.txt, kind: security.txt, http_status: 404}