generated: '2026-08-13' method: searched probe: true source: https://www.salesloft.com/security description: >- Salesloft publishes a substantive public security-program page and states on it that it runs an ongoing bug-bounty program with independent penetration testers, plus annual third-party security assessments. What it does NOT publish is a way in: there is no /.well-known/security.txt on any Salesloft host, no responsible-disclosure or vulnerability-disclosure-policy page, no public HackerOne or Bugcrowd program, and no security@ contact address anywhere on the public site. A researcher who finds a bug in Salesloft today has no published intake channel. policy: - https://www.salesloft.com/security contact: [] security_txt: false bug_bounty: claimed: true public_program: false platform: null quote: >- "our bug-bounty program entails penetration testing by independent security professionals on an ongoing basis; and security assessments are performed on a project basis at least annually by a reputable independent security-consulting firm. Reported vulnerabilities are assessed, prioritized based on risk, and tracked through dispensation." security_program: data_centers: 'AWS and GCP, US and EU (Drift on AWS, US)' encryption_in_transit: 'HTTPS / TLS 1.2+' encryption_at_rest: 'AES-256-GCM, plus IaaS disk-level encryption; keys managed and auto-rotated by the provider KMS' team: 'Information Security team under the CIO — Security Engineering, Security Operations, and GRC' monitoring: 'WAF, SCA/dependency scanning, log aggregation, EDR/XDR, PAM, SIEM with 24x365 partner monitoring and on-call escalation' access_control: 'Least access required; production access via PAM with role-based permissions, approval groups, time-limited sessions and MFA' sdlc: 'Mandatory secure-development training; CI/CD with automated code scans, peer review and QA approval gates' certifications_page: https://trust.salesloft.com/ evidence: - {source: 'https://www.salesloft.com/security', kind: security-program-page, status: 200, keywords: [bug-bounty, penetration testing, reported vulnerabilities, security assessments]} - {source: 'https://trust.salesloft.com/', kind: trust-center, status: 200} gaps: - {check: '/.well-known/security.txt on www.salesloft.com', status: 404} - {check: '/.well-known/security.txt on api.salesloft.com', status: 401} - {check: '/.well-known/security.txt on developers.salesloft.com', status: 404} - {check: 'https://hackerone.com/salesloft', status: 404} - {check: 'https://bugcrowd.com/salesloft', status: 404} - {check: 'https://www.salesloft.com/legal/responsible-disclosure', status: 404} - {check: 'https://www.salesloft.com/responsible-disclosure', status: 404} - {check: 'https://www.salesloft.com/legal/vulnerability-disclosure-policy', status: 404} recommendation: >- Publishing an RFC 9116 /.well-known/security.txt with a Contact and a Policy URL would close this in an afternoon and is the single cheapest security-posture improvement available to Salesloft — the program already exists; only the front door is missing. x-evidence: fetched: '2026-08-13'