generated: '2026-08-27' method: searched source: https://redocly.com/vulnerability-disclosure-policy (fetched 2026-08-27, HTTP 200) provider: Redocly providerId: redocly name: Redocly Vulnerability Disclosure Policy url: https://redocly.com/vulnerability-disclosure-policy markdown_url: https://redocly.com/vulnerability-disclosure-policy.md contact: security@redocly.com description: >- Redocly publishes a full CISA-style vulnerability disclosure policy with a named security contact, an explicit safe-harbour authorization clause, a defined scope list and out-of-scope rules. It is a real programme document, not a boilerplate contact line — but it is NOT discoverable the standard way: /.well-known/security.txt returns 404 on redocly.com, so a scanner following RFC 9116 finds nothing. program: type: vulnerability-disclosure-policy bug_bounty: false platform: none note: >- No HackerOne, Bugcrowd or Intigriti programme was found. Reports go directly to security@redocly.com. safe_harbour: authorized: true text: >- Good-faith research in compliance with the policy is considered authorized; Redocly will not recommend or pursue legal action, and will make the authorization known if a third party initiates action. scope: in_scope: - app.redocly.com - api.redoc.ly - api.redocly.com - ssl.redoc.ly - ssl.redocly.com - app.cloud.redocly.com - Redocly Slack App - github.com/Redocly (any publicly accessible repository) out_of_scope: - All other subdomains - All customer applications - Connected services and vendor systems note: >- Redocly is hosted on AWS and asks researchers to also comply with AWS vulnerability reporting policies. prohibited_test_methods: - Network denial of service (DoS/DDoS) or any test that impairs access or damages a system or data - Physical testing, social engineering, phishing, vishing, and other non-technical testing researcher_obligations: - Notify Redocly as soon as possible after discovering a real or potential issue. - Avoid privacy violations, UX degradation, production disruption, and destruction or manipulation of data. - Use exploits only to the extent needed to confirm the vulnerability; no exfiltration, persistence or pivoting. - Allow reasonable time to resolve before public disclosure. - Stop testing and notify immediately on encountering sensitive data. - Do not submit a high volume of low-quality reports. gaps: - >- /.well-known/security.txt returned 404 on redocly.com on 2026-08-27. The policy exists but is not machine-discoverable under RFC 9116; adding a security.txt with Contact and Policy fields would close this at zero cost.