generated: '2026-08-13' method: searched source: https://www.setsail.co/legal/vulnerability-reporting-policy probe: true policy: - https://www.setsail.co/legal/vulnerability-reporting-policy contact: - security@setsail.co bug_bounty: false bug_bounty_note: >- No bug bounty platform (HackerOne, Bugcrowd, Intigriti) is referenced; SetSail runs a direct-email responsible-disclosure program only. security_txt: false security_txt_note: >- https://www.setsail.co/.well-known/security.txt returns 404 with an "Invalid .well-known request" body — the RFC 9116 file is not served, so the policy is discoverable only from the site's legal section. policy_summary: reporting_channel: email acknowledgement: >- Commits to acknowledge receipt, give an estimated remediation timeframe, and notify the reporter when the vulnerability is fixed. safe_harbor_stated: false out_of_scope: - non-exploitable vulnerabilities - missing security headers / best-practice violations - SSL/TLS configuration issues (weak cipher suites) - fingerprinting and banner disclosure on common or public services - self-XSS - internal IP disclosure - CSRF - error messages with non-sensitive data prohibited_conduct: - spam, brute force, denial of service - accessing data that does not belong to the researcher - destroying or corrupting data - physical or electronic attack on personnel, property or data centers - social engineering of service desk, employees or contractors - testing with anything other than test accounts evidence: - source: https://www.setsail.co/legal/vulnerability-reporting-policy kind: disclosure-policy-page http_status: 200 keywords: - responsible reporting of vulnerabilities - security@setsail.co - security researchers - source: https://www.setsail.co/.well-known/security.txt kind: security.txt http_status: 404 notes: - >- https://www.setsail.co/security 301-redirects to https://security.setsail.co/, a SafeBase trust portal (CNAME setsail.portals.safebase.io) that now returns HTTP 404 — the trust center was published at some point and is no longer reachable, so no TrustCenter artifact was written from it. - >- SetSail is joining ZoomInfo (stated in the site-wide banner); the site footer points privacy, terms and trust center at zoominfo.com while the vulnerability reporting policy remains SetSail-branded and SetSail-operated.