generated: '2026-08-13' method: searched probe: true source: https://www.sendible.com/vulnerability-reporting name: Sendible Vulnerability Reporting Policy policy: - https://www.sendible.com/vulnerability-reporting contact: - security@sendible.com bug_bounty: false compensation: none safe_harbor: true scope: testing_requirement: >- All vulnerability testing must be conducted against test or trial accounts where one is available. prohibited: - Actions that may negatively affect Sendible or its users (spam, brute force, denial of service) - Accessing, or attempting to access, data that does not belong to you - Destroying or corrupting data that does not belong to you - Physical or electronic attacks on Sendible personnel, property or data centres - Social engineering of any Sendible employee or contractor - Testing participating services with anything other than a test or trial account - Violating laws or breaching agreements in order to discover vulnerabilities commitments: - Sendible pledges not to initiate legal action against researchers who adhere to the policy. - Sendible will acknowledge receipt of a report and notify the reporter when the vulnerability is fixed. - Researchers are asked not to publicise an unresolved vulnerability to third parties. security_txt: false evidence: - {source: 'https://www.sendible.com/vulnerability-reporting', http_status: 200, kind: disclosure-policy-page} - {source: 'https://www.sendible.com/privacy', http_status: 200, kind: privacy-policy-section, note: 'section 11, "Vulnerability reporting policy", links to the policy page'} - {source: 'https://www.sendible.com/.well-known/security.txt', http_status: 404, kind: security-txt-absent} note: >- Sendible publishes a real, first-party responsible-disclosure policy with a named security contact and an explicit safe-harbour pledge, but does NOT serve an RFC 9116 /.well-known/security.txt — a researcher who follows the standard discovery path will not find it. The automated probe (0-working/probe-security-programs.py) missed this page because it lives at /vulnerability-reporting, which is not one of the paths it checks; it was found by reading section 11 of the privacy policy.