generated: '2026-06-20' method: searched probe: true source: >- https://www.twilio.com/docs/usage/security/reporting-vulnerabilities and https://hackerone.com/twilio — SendGrid is a Twilio company and is covered by Twilio's platform-wide security programs. description: >- SendGrid does not publish its own /.well-known/security.txt (returns HTTP 403) or a SendGrid-branded disclosure page. Vulnerability reporting is handled through Twilio's platform-wide programs, which explicitly cover SendGrid. Twilio runs a paid bug bounty on HackerOne and a separate public Vulnerability Disclosure Program (no monetary reward). programs: - name: Twilio Bug Bounty (HackerOne) type: bug-bounty url: https://hackerone.com/twilio reward: monetary (severity/impact based) note: Researchers sign up on HackerOne and accept the Twilio Terms of Service. - name: Twilio Vulnerability Disclosure Program type: vulnerability-disclosure url: https://www.twilio.com/docs/usage/security/reporting-vulnerabilities reward: none note: Open to customers, researchers, and the public. covers_sendgrid: true security_txt: published: false probe_status: 403 hosts_probed: [https://api.sendgrid.com, https://sendgrid.com] evidence: - {source: https://www.twilio.com/docs/usage/security/reporting-vulnerabilities, kind: disclosure-page} - {source: https://hackerone.com/twilio, kind: bug-bounty}