generated: '2026-08-13' method: searched source: https://sendpulse.com/security.txt + https://sendpulse.com/legal/security security_txt: url: https://sendpulse.com/security.txt http_status: 200 file: ../well-known/sendpulse-security.txt canonical_path: false fields: Contact: support@sendpulse.com OpenBugBounty: https://openbugbounty.org/bugbounty/SendPulseCom/ deviations: - Served at /security.txt, not the RFC 9116 path /.well-known/security.txt (that path returns 404). - No Expires field — RFC 9116 requires one. - No Policy, Encryption, Preferred-Languages or Canonical field. bug_bounty: program: Open Bug Bounty url: https://openbugbounty.org/bugbounty/SendPulseCom/ paid: true note: The SendPulse Security page states researchers who find security bugs "can receive a financial reward". disclosure_page: url: https://sendpulse.com/legal/security http_status: 200 note: Describes vulnerability management with automated and manual remediation processes. contact: support@sendpulse.com