generated: '2026-08-13' method: searched probe: true source: https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html scope_note: >- Responsys has no product-specific disclosure program. Vulnerability reporting for Responsys runs through Oracle's corporate Global Product Security process, which covers every Oracle product. Recorded here at the corporate level because that is where the provider actually publishes it. policy: - https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html - https://www.oracle.com/corporate/security-practices/assurance/vulnerability/ contact: - secalert_us@oracle.com channels: - kind: service-request detail: >- Oracle customers and partners submit security vulnerabilities through My Oracle Support as a service request. url: https://support.oracle.com/ - kind: email detail: >- Non-customers email secalert_us@oracle.com. Oracle encourages reporters to encrypt sensitive vulnerability information — reports, proof-of-concept details, logs and attachments — with Oracle's public PGP key before transmission. contact: secalert_us@oracle.com bug_bounty: offered: false note: >- Oracle runs no paid bug bounty. It offers researcher credit instead, published in the quarterly Critical Patch Update / Security Alert advisories, conditional on responsible disclosure — not publishing the vulnerability before Oracle releases a fix, and not disclosing exact exploit details. remediation_cadence: scheme: Critical Patch Update frequency: quarterly note: Fixes and researcher credit ship in the quarterly CPU or an out-of-band Security Alert. security_txt: served: false note: >- No /.well-known/security.txt is served on any host in this profile — see well-known/responsys-well-known.yml. The disclosure program is real but is published as HTML only, not in RFC 9116 machine-readable form. evidence: - {source: 'https://www.oracle.com/corporate/security-practices/assurance/vulnerability/reporting.html', status: 200, keywords: [secalert_us@oracle.com, PGP, responsible disclosure, vulnerability]} - {source: 'https://www.oracle.com/corporate/security-practices/assurance/vulnerability/', status: 200}