generated: '2026-08-26' method: searched source: https://muckrack.com/responsible-disclosure docs: https://muckrack.com/responsible-disclosure published: true policy_url: https://muckrack.com/responsible-disclosure contact: security@muckrack.com contact_type: email bug_bounty: false rewards: false rewards_note: >- "Muck Rack does not offer monetary compensation for reports at this time." No HackerOne, Bugcrowd or Intigriti program was found. safe_harbor: true safe_harbor_note: >- "Muck Rack will not engage in legal action against individuals who submit vulnerability reports through our Vulnerability Reporting inbox", conditional on the reporter adhering to the laws of their location and Muck Rack's, and refraining from public disclosure before a mutually agreed timeframe expires. coordinated_disclosure: true response_sla: null response_sla_note: >- No response timeframe is committed. The policy says only that Muck Rack "will provide an update on the status of the vulnerability" if necessary or if requested by the reporter in writing. out_of_scope: - Denial of service / DDoS - Spamming - Social engineering and phishing - Automated vulnerability scanning - Attacks on physical property or data centers security_txt: served: false path: /.well-known/security.txt status: 404 note: >- THE DISCOVERABILITY GAP. A real, well-formed responsible disclosure policy with a dedicated security@ inbox and safe harbor exists — but it is not reachable at the RFC 9116 well-known location, so no automated scanner or agent can find it. Publishing a two-line security.txt pointing Contact: and Policy: at what already exists would close this at essentially zero cost. also_referenced_from: https://muckrack.com/legal-and-security