specification: API Commons Vulnerability Disclosure specificationVersion: '0.1' provider: LaunchDarkly providerId: launchdarkly generated: '2026-08-27' method: searched source: https://hackerone.com/launchdarkly http_status: 200 checked: '2026-08-27' published: true program: type: bug-bounty platform: HackerOne url: https://hackerone.com/launchdarkly name: LaunchDarkly Bug Bounty Program evidence: >- The HackerOne program page returns 200 and its own meta description reads "The LaunchDarkly Bug Bounty Program enlists the help of the hacker community at HackerOne to make LaunchDarkly more secure." This is a managed, named program on a third-party platform, not a mailto on a marketing page. managed_by: HackerOne security_txt: published: false probes: - url: https://launchdarkly.com/.well-known/security.txt status: 404 - url: https://launchdarkly.com/security.txt status: 404 - url: https://app.launchdarkly.com/.well-known/security.txt status: 404 finding: >- LaunchDarkly runs a real bug bounty program but publishes NO RFC 9116 security.txt pointing at it. A researcher — or an agent — following the standard discovery path finds nothing on any LaunchDarkly host and has to already know the HackerOne handle. This is the cheapest gap in the provider's security posture to close: one static file with a Contact and Policy line. related_probes: - url: https://launchdarkly.com/security/vulnerability-disclosure/ status: 404 - url: https://launchdarkly.com/policies/vulnerability-disclosure-policy/ status: 404 - url: https://bugcrowd.com/launchdarkly status: 404 note: Checked to rule out a second program; none exists. security_page: url: https://launchdarkly.com/security/ status: 200 trust_center: security/launchdarkly-trust-center.yml