generated: '2026-08-26' method: searched source: https://www.roserocket.com/responsible-disclosure source_status: 200 probed: '2026-08-26' description: >- Rose Rocket runs a real, published responsible-disclosure program with a dedicated intake address, a stated list of what to include in a report, and an explicit acknowledgement commitment. It is not a bug bounty and the company says so outright. The program's one machine-readability gap is that it is HTML only: /.well-known/security.txt returns 404 on every Rose Rocket host, so a scanner or an agent looking for the RFC 9116 discovery path finds nothing and would conclude — wrongly — that no disclosure policy exists. program: exists: true type: responsible disclosure policy_url: https://www.roserocket.com/responsible-disclosure contact: responsibledisclosure@roserocket.com contact_type: email statement: >- "At Rose Rocket, we deeply value the security of your information. Therefore, we encourage anyone who believes they have discovered potential security vulnerabilities to report them to us and help us improve and maintain our security measures." requested_report_contents: - Detailed description of your discovery - The applicable URL at which you discovered the vulnerability - Any relevant screen captures / screen recordings - Steps taken to identify the vulnerability - Tools used - Any other relevant information or details acknowledgement: >- "Once we receive your report, we will acknowledge receipt with an automated reply. Our team will make our best effort to investigate and address any identified vulnerabilities in a timely manner." response_sla: none stated (best effort) safe_harbor: not stated scope_definition: not published hall_of_fame: none bug_bounty: exists: false statement: >- "Please note that Rose Rocket does not currently operate a 'Bug Bounty' program. We make no offer of reward or compensation in exchange for submitting potential vulnerabilities." platforms_checked: [HackerOne, Bugcrowd, Intigriti] platforms_result: no program found security_txt: published: false rfc9116: false probes: - {url: 'https://www.roserocket.com/.well-known/security.txt', status: 404} - {url: 'https://roserocket.com/.well-known/security.txt', status: 404} - {url: 'https://network.roserocket.com/.well-known/security.txt', status: 404} - {url: 'https://a.roserocket.com/.well-known/security.txt', status: 404} - {url: 'https://platform.roserocket.com/.well-known/security.txt', status: 404} - {url: 'https://roserocket.readme.io/.well-known/security.txt', status: 404} recommendation: >- A one-line security.txt at https://www.roserocket.com/.well-known/security.txt with Contact: mailto:responsibledisclosure@roserocket.com and Policy: https://www.roserocket.com/responsible-disclosure would make an existing, working program discoverable by machine. The content already exists; only the discovery path is missing. related: trust_center: exists: false note: >- No trust centre portal. trust.roserocket.com resolves (HTTP 200) but returns the Rose Rocket application shell, not a trust page — a wildcard host, not a program. certifications: - {name: SOC 2, claimed: true, evidence: 'https://www.roserocket.com/solutions/security', detail: See conformance/rose-rocket-conformance.yml.}