generated: '2026-08-13' method: searched source: https://www.semrush.com/company/security/ provider: Semrush providerId: semrush description: >- Semrush runs a coordinated vulnerability disclosure program on HackerOne and publishes a named security contact on its public security page. It does not serve a /.well-known/security.txt on any host, so an automated scanner following RFC 9116 finds nothing — the program is discoverable only by reading the marketing site. program: exists: true type: bug-bounty platform: HackerOne url: https://hackerone.com/semrush policy_url: https://www.semrush.com/company/security/ contact: security@semrush.com description: >- "A Bug Bounty program invites and incentivizes independent security researchers to ethically discover and disclose security flaws. Semrush has implemented a Bug Bounty program." — semrush.com/company/security/ safe_harbor_published: false scope_published: false rewards_published: false note: >- Terms, scope and bounty ranges are held on the HackerOne program page, which is JavaScript-rendered and returned no readable policy text to an unauthenticated fetch. security_txt: served: false hosts_probed: - host: www.semrush.com path: /.well-known/security.txt status: 404 - host: api.semrush.com path: /.well-known/security.txt status: 400 - host: developer.semrush.com path: /.well-known/security.txt status: 404 - host: mcp.semrush.com path: /.well-known/security.txt status: 401 note: >- RFC 9116 gap. Semrush has a real disclosure program and a real security contact but publishes neither at the machine-readable location, so the program cannot be discovered programmatically. related_practices: - name: Penetration testing detail: The security team penetration-tests new features weekly, per release policy. - name: Patch management detail: >- Documented process for monitoring security vulnerabilities and testing and deploying patches or configuration changes across company infrastructure. x-evidence: - url: https://www.semrush.com/company/security/ http_status: 200 - url: https://hackerone.com/semrush http_status: 200 note: Page loads but is JS-rendered; no policy text available to an unauthenticated fetch. - url: https://www.semrush.com/.well-known/security.txt http_status: 404 checked: '2026-08-13'