generated: '2026-08-13' method: searched probe: true source: https://www.rudderstack.com/vulnerability-disclosure-policy/ url: https://www.rudderstack.com/vulnerability-disclosure-policy/ http_status: 200 description: >- RudderStack publishes a named Vulnerability Disclosure Policy, linked from the site footer on every page. It defines a security vulnerability, states the scope ("any digital assets owned, operated, or maintained by RudderStack, including public facing websites"), sets out four mutual commitments (Trust, Respect, Transparency, Common Good) in both directions, and asks researchers to report through a web form on the policy page. RudderStack commits to acknowledge receipt of each report, investigate, and act. policy_published: true scope: Any digital asset owned, operated, or maintained by RudderStack, including public-facing websites. reporting: method: web form on the policy page email: null note: >- No dedicated security@ address is published on the policy page and there is no /.well-known/security.txt on any RudderStack host, so the form is the only named channel. safe_harbor: stated: partial note: >- The policy frames researcher protection as mutual commitments rather than an explicit legal safe-harbour clause. It asks researchers to avoid privacy violations, UX degradation, production disruption and data destruction, and to withhold public disclosure until RudderStack has validated and addressed the issue. acknowledgement_commitment: RudderStack will acknowledge receipt of each vulnerability report. bug_bounty: program: false platform: null note: No HackerOne, Bugcrowd or Intigriti program was found. security_txt: published: false probed: - {url: 'https://www.rudderstack.com/.well-known/security.txt', status: 404} - {url: 'https://api.rudderstack.com/.well-known/security.txt', status: 404} evidence: - source: https://www.rudderstack.com/vulnerability-disclosure-policy/ http_status: 200 kind: disclosure policy page keywords: - vulnerability disclosure policy - security researchers - security vulnerability - responsible manner - vulnerability reporting - source: https://www.rudderstack.com/security/ http_status: 200 kind: security overview page linking the disclosure policy