generated: '2026-08-12' method: searched probe: true source: https://leadpages.com/security policy: - https://leadpages.com/security contact: - security@leadpages.com program: type: responsible-disclosure bug_bounty: false bounty_platform: null paid_rewards: false note: >- A responsible-disclosure program published in HTML on the security page. No bug bounty: no HackerOne, Bugcrowd or Intigriti presence was found, and no monetary reward is offered — recognition only. intake: channel: email address: security@leadpages.com instructions_verbatim: >- Email us at security@leadpages.com with a detailed description of the issue, including steps to reproduce if possible. commitments: acknowledgement: within 2 business days status_update: within 5 business days safe_harbor: >- "We will not take legal action against good-faith researchers." — a safe-harbor statement, though it is not expressed in formal safe-harbor or CVD-policy terms. credit: Credit given in our security acknowledgments (if desired) researcher_guidelines: - Do not publicly disclose the vulnerability until we have had a chance to address it. - Do not access or modify other users' data. - Do not perform actions that could harm the availability of our service. gaps: - id: no-security-txt detail: >- https://leadpages.com/.well-known/security.txt returns 404. The program exists but is not discoverable by an RFC 9116 machine client — a one-file fix that would make the disclosure contact automatically findable. probe: {url: 'https://leadpages.com/.well-known/security.txt', status: 404} evidence: - source: https://leadpages.com/security kind: disclosure page http_status: 200 keywords: [responsible disclosure, vulnerability, security@, good-faith researchers] x-evidence: fetched: '2026-08-12' probes: - {url: 'https://leadpages.com/security', status: 200} - {url: 'https://leadpages.com/.well-known/security.txt', status: 404}