generated: '2026-08-13' method: searched probe: true source: https://www.klaviyo.com/security/bug-reporting program: published: true type: managed bug bounty + coordinated vulnerability disclosure platform: Bugcrowd platform_url: https://bugcrowd.com/engagements/klaviyo-og platform_engagement_name: Klaviyo Managed Bug Bounty access: invite-only access_detail: >- The Bugcrowd bounty program is invite-only. Researchers who are not invited submit suspected vulnerabilities through the public web form at https://www.klaviyo.com/security/bug-reporting, so the disclosure channel itself is open even though the paid program is not. public_disclosure_permitted: true public_disclosure_note: Governed by Bugcrowd's standard disclosure guidelines. policy: - https://www.klaviyo.com/security/bug-reporting - https://bugcrowd.com/engagements/klaviyo-og contact: - security@klaviyo.com contact_other: - {address: abuse@klaviyo.com, purpose: abuse and spam reports (not security vulnerabilities)} security_txt: served: false detail: >- Klaviyo does NOT publish an RFC 9116 security.txt. /.well-known/security.txt returns 404 on www.klaviyo.com, klaviyo.com and a.klaviyo.com; developers.klaviyo.com returns 200 but with the ReadMe.io HTML SPA shell, which is not a document. This is the one gap in an otherwise well-published program — a machine reading only /.well-known/security.txt would conclude Klaviyo has no disclosure channel. probes: - {url: 'https://www.klaviyo.com/.well-known/security.txt', status: 404} - {url: 'https://klaviyo.com/.well-known/security.txt', status: 404} - {url: 'https://a.klaviyo.com/.well-known/security.txt', status: 404} - {url: 'https://developers.klaviyo.com/.well-known/security.txt', status: 200, content_type: text/html, verdict: SPA shell — not a document} additional_assurance: - Annual third-party penetration testing - Bug bounty program with external security researchers evidence: - {source: 'https://www.klaviyo.com/security/bug-reporting', http_status: 200, keywords: [bug bounty, BugCrowd, vulnerability disclosure, invite only, security@klaviyo.com]} - {source: 'https://www.klaviyo.com/trust', http_status: 200, keywords: [bug bounty, security@klaviyo.com]} - {source: 'https://bugcrowd.com/engagements/klaviyo-og', http_status: 200, keywords: [Bug Bounty, Bugcrowd VRT, public disclosure is permitted]} - {source: 'https://www.klaviyo.com/security', http_status: 200, keywords: [security@klaviyo, vulnerability]} x-evidence: fetched: '2026-08-13'