generated: '2026-08-13' method: searched probe: true source: https://moosend.com/privacy-policy/disclosure/ policy: - https://moosend.com/privacy-policy/disclosure/ submission_form: - https://moosend.com/disclosure/ contact: [] contact_note: >- No security@ address is published. Reports are submitted through a web form at https://moosend.com/disclosure/, which forwards to Bugcrowd. programme: type: vulnerability-disclosure-programme platform: Bugcrowd bug_bounty: false rewards: >- Explicitly not a bug bounty. Researchers receive Bugcrowd points for validly accepted reports; there is no monetary reward. "Moosend reserves the right to accept or reject any submission." severity_taxonomy: Bugcrowd Vulnerability Rating Taxonomy (VRT) safe_harbor: true safe_harbor_quote: >- Research conducted in accordance with the policy is "Authorized in accordance with the Computer Fraud and Abuse Act (CFAA)", "Exempt from the Digital Millennium Copyright Act (DMCA)", "Exempt from restrictions in our Terms of Service", and "Lawful, helpful to the overall security of the Internet, and conducted in good faith." out_of_scope: - CSRF on anonymous forms - Public file disclosure - SSL/TLS configuration suggestions - SPF/DMARC configuration suggestions - Phishing techniques security_txt: served: false probed: - {url: 'https://moosend.com/.well-known/security.txt', status: 404} - {url: 'https://api.moosend.com/.well-known/security.txt', status: 404} - {url: 'https://docs.moosend.com/.well-known/security.txt', status: 404} note: >- The policy exists but is not machine-discoverable. An RFC 9116 security.txt naming Policy: https://moosend.com/privacy-policy/disclosure/ would close the gap with no new programme work. evidence: - source: https://moosend.com/privacy-policy/disclosure/ http_status: 200 kind: disclosure-policy keywords: [vulnerability disclosure, bugcrowd, safe harbor, cfaa, dmca, submission form] fetched: '2026-08-13' - source: https://moosend.com/disclosure/ http_status: 200 kind: submission-form fetched: '2026-08-13'