generated: '2026-08-27' method: searched source: >- https://hackerone.com/netlify (HTTP 200, 2026-08-27) and https://www.netlify.com/security/ (HTTP 200), cross-checked against the /.well-known/security.txt probe recorded in well-known/netlify-well-known.yml. description: >- Netlify runs a public bug bounty programme hosted on HackerOne. It does not advertise that programme through RFC 9116 — no host Netlify serves answers /.well-known/security.txt — so the route is discoverable by a human reading the security page, but not by a scanner following the standard path. program: exists: true type: bug-bounty platform: HackerOne url: https://hackerone.com/netlify name: Netlify Bug Bounty Program public: true evidence: - url: https://hackerone.com/netlify status: 200 detail: >- Page title "Netlify - Bug Bounty Program | HackerOne"; description reads "The Netlify Bug Bounty Program enlists the help of the hacker community at HackerOne to make Netlify more secure." security_txt: served: false probed_hosts: - host: api.netlify.com status: 404 - host: www.netlify.com status: 404 - host: netlify.com status: 404 - host: docs.netlify.com status: 404 - host: open-api.netlify.com status: 404 - host: developers.netlify.com status: 404 - host: app.netlify.com status: 200 served: false note: SPA catch-all returns 200 with an HTML shell for every /.well-known/ path. also_probed: - url: https://www.netlify.com/security.txt status: 404 - url: https://www.netlify.com/legal/vulnerability-disclosure-policy/ status: 404 - url: https://www.netlify.com/security/responsible-disclosure/ status: 404 gap: >- The programme is real; the discovery document is missing. Publishing a security.txt naming the HackerOne policy URL would close this with one file. contacts: - type: dns-caa-iodef value: mailto:security@netlify.com source: >- CAA record on netlify.com — `128 iodef "mailto:security@netlify.com"`, observed by probe-domain-security.py on 2026-08-27. This is an incident-reporting address for certificate issuance problems, not a stated vulnerability-disclosure inbox, and it is recorded here only because it is the sole security address Netlify publishes in a machine-readable place. security_page: https://www.netlify.com/security/ security_page_markdown: https://www.netlify.com/security.md trust_center: https://trust.netlify.com/ detail: security/netlify-trust-center.yml