generated: '2026-08-26' method: searched source: https://rampnetwork.com/security program: published: true reporting_email: security@ramp.network disclosure_page: https://rampnetwork.com/security security_txt: null security_txt_note: >- No RFC 9116 /.well-known/security.txt is served on any Ramp Network host — apex, www, api and api.demo all returned 404 on 2026-08-26. The disclosure route exists, it is just not machine-discoverable at the well-known path. bug_bounty: platform: Intigriti url: https://app.intigriti.com/researcher/programs/rampnetwork/rampnetworkvdp scope_visibility: private launched: '2024-10-02' announcement: https://rampnetwork.com/blog/bug-bounty-program note: >- Ramp Network runs a PRIVATE bug bounty / vulnerability disclosure program on Intigriti, announced 2 October 2024 by their Head of Information Security. Researchers are invited rather than self-serve; the announcement directs prospective participants to security@ramp.network. Rewards are stated to be severity-based, but no published bounty table was found. practices_published: - penetration testing by third-party experts - static code analysis in the SDLC - documented incident response process - encryption in transit and at rest evidence: - url: https://rampnetwork.com/security status: 200 detail: >- "Reporting issues and vulnerabilities ... please report by sending an email to security@ramp.network or to our Vulnerability Disclosure Program", linking app.intigriti.com/researcher/programs/rampnetwork/rampnetworkvdp - url: https://rampnetwork.com/blog/bug-bounty-program status: 200 detail: Launch announcement of the private Intigriti bug bounty program - url: https://rampnetwork.com/.well-known/security.txt status: 404