generated: '2026-08-27' method: searched source: https://www.salesforce.com/company/disclosure/ program: published: true name: Salesforce Responsible Disclosure Policy url: https://www.salesforce.com/company/disclosure/ http_status: 200 probed: '2026-08-27' submission_url: https://sfdc.co/SubmitVuln submission_http_status: 200 safe_harbor: true safe_harbor_quote: >- "Salesforce pledges not to initiate legal action against researchers for penetrating or attempting to penetrate our systems as long as they adhere to this policy." process_quote: >- "share details of the suspected vulnerability with Salesforce by submitting the details at https://sfdc.co/SubmitVuln ... Provide full details of the suspected vulnerability so the Salesforce security team may validate and reproduce the issue" testing_guidance_quote: >- "Whenever a Trial or Developer Edition is available, please conduct all vulnerability testing against such instances. Always use test or demo accounts when testing." prohibited: >- Actions that may negatively affect Salesforce or its users — spam, brute force, denial of service — are expressly prohibited. A Security Assessment Agreement must be reviewed before testing. agreements: - name: Responsible Disclosure Policy url: https://www.salesforce.com/company/disclosure/ - name: Security Assessment Agreement url: https://www.salesforce.com/company/disclosure/ bug_bounty: platform: null url: null note: >- NOT CONFIRMED. hackerone.com/salesforce returns an HTTP 200 SPA shell but hackerone.com/salesforce.json returns 404, so no public HackerOne program could be verified from the platform's own API, and the disclosure policy page itself does not name a bounty platform or a reward table. Recorded as unknown rather than claimed. evidence: - {url: 'https://hackerone.com/salesforce', status: 200, note: 'SPA shell, not a program page'} - {url: 'https://hackerone.com/salesforce.json', status: 404} security_txt: served: false probed: - {url: 'https://www.salesforce.com/.well-known/security.txt', status: 302} - {url: 'https://api.salesforce.com/.well-known/security.txt', status: 404} - {url: 'https://login.salesforce.com/.well-known/security.txt', status: 404} - {url: 'https://trust.salesforce.com/.well-known/security.txt', status: 404} - {url: 'https://developer.salesforce.com/.well-known/security.txt', status: 403, note: bot challenge} gap: >- A company running a formal responsible-disclosure programme with a safe-harbour pledge publishes no RFC 9116 security.txt on any of its primary hosts. Adding one at www.salesforce.com pointing Policy: at /company/disclosure/ and Contact: at sfdc.co/SubmitVuln would be a one-file fix. security_portal: url: https://security.salesforce.com/ http_status: 200 probed: '2026-08-27'