generated: '2026-09-13' method: searched source: https://www.proofpoint.com/us/security/vulnerability-disclosure-policy name: Proofpoint Vulnerability Disclosure Policy policy: - https://www.proofpoint.com/us/security/vulnerability-disclosure-policy contact: - mailto:security@proofpoint.com program: type: vulnerability-disclosure-policy bug_bounty: unconfirmed platform: HackerOne platform_url: https://hackerone.com/proofpoint platform_note: 'A HackerOne page exists at hackerone.com/proofpoint and returns HTTP 200, but the page body is a JavaScript shell ("It looks like your JavaScript is disabled") so the program scope, bounty table and status could not be read without a browser. Recorded as present-but-unread rather than as a confirmed paid bounty.' hall_of_fame: true cve_issuance: true scope: included: Proofpoint Products excluded: Third party products note: 'Policy text: "This Policy applies to Proofpoint Products. Third party products are excluded from the scope of this Policy." Researchers unsure whether a system is in scope are told to contact security@proofpoint.com before starting.' researcher_obligations: - Cease further testing and promptly submit a report to security@proofpoint.com - No social engineering, physical security testing or other non-technical security testing researcher_benefits: - Recognition on Proofpoint's Hall of Fame (with permission) - CVE identifiers for legitimate vulnerabilities in Proofpoint Products, publicly disclosed via Proofpoint Security Advisories evidence: - url: https://www.proofpoint.com/us/security/vulnerability-disclosure-policy http_status: 200 kind: published vulnerability disclosure policy - url: https://hackerone.com/proofpoint http_status: 200 kind: bug bounty platform page (JS-rendered, body unread) - url: https://www.proofpoint.com/us/security http_status: 200 kind: Proofpoint Security hub x-correction: note: 'CORRECTED 2026-09-13. probe-security-programs.py first wrote this file crediting Proofpoint with a security.txt at https://help.proofpoint.com/.well-known/security.txt. That document is real and returns HTTP 200, but it belongs to NICE, not Proofpoint: it declares Contact mailto:ExpertSecurity@nice.com and Policy https://expert-help.nice.com/Admin/Contact/Disclosure. help.proofpoint.com is a MindTouch / NICE CXone Expert tenant and the platform serves its own security.txt on every customer subdomain. Proofpoint itself serves no security.txt on any host probed (see well-known/proofpoint-well-known.yml); its real disclosure policy is an HTML page on www.proofpoint.com.'