generated: '2026-08-13' method: searched probe: true source: https://www.salesforce.com/company/disclosure/ note: >- The mechanical probe (probe-security-programs.py) reported vdp=none for this slug because Salesforce serves no /.well-known/security.txt (404 on www.salesforce.com, 403 bot wall on developer.salesforce.com) and its disclosure content sits at a non-standard path. Verified by hand on 2026-08-13: Salesforce runs both a public responsible-disclosure page and a managed HackerOne program. security_txt: false security_txt_note: >- https://www.salesforce.com/.well-known/security.txt returned HTTP 404 on 2026-08-13. Salesforce publishes a disclosure policy but does not advertise it via RFC 9116, so a machine following the standard discovery path finds nothing. policy: - https://www.salesforce.com/company/disclosure/ - https://security.salesforce.com/ bug_bounty: platform: HackerOne url: https://hackerone.com/salesforce handle: salesforce program_id: 948 managed: true allows_disclosure_assistance: true evidence: - source: https://www.salesforce.com/company/disclosure/ kind: disclosure-page status: 200 keywords: [Responsible Disclosure] fetched: '2026-08-13' - source: https://security.salesforce.com/ kind: security-portal status: 200 keywords: [Responsible Disclosure, GDPR] fetched: '2026-08-13' - source: https://hackerone.com/salesforce kind: bug-bounty status: 200 keywords: [HackerOne, bug bounty, responsible disclosure] fetched: '2026-08-13' detail: >- HackerOne program API returned {"id":948,"name":"Salesforce","handle":"salesforce", "allows_disclosure_assistance":true}. - source: https://www.salesforce.com/.well-known/security.txt kind: security.txt status: 404 fetched: '2026-08-13'