generated: '2026-08-14' method: searched probe: true source: https://www.showpad.com/responsible-disclosure policy: - https://www.showpad.com/responsible-disclosure - https://app.intigriti.com/programs/showpad/vdp/detail program: type: vulnerability-disclosure-program platform: Intigriti url: https://app.intigriti.com/programs/showpad/vdp/detail bounty: not stated contact: - https://app.intigriti.com/programs/showpad/vdp/detail - security@showpad.com contact_note: >- security@showpad.com is published by Showpad in DNS as the CAA iodef contact for showpad.com (`0 iodef "mailto:security@showpad.com"`). The responsible-disclosure page directs researchers to the Intigriti program rather than to an email address. commitments: acknowledgement: We will do our best to acknowledge receipt of your report within three business days. updates: Progress updates provided throughout remediation. anonymity: Researcher identity protected unless legally required; findings may use aliases. safe_harbor: >- "We will not undertake any legal action if you accept and apply all the rules above" — conditional on following the published do's and don'ts (no exploitation, no unauthorized access, no denial-of-service, no data modification). evidence: - source: https://www.showpad.com/responsible-disclosure kind: disclosure-page http_status: 200 keywords: [responsible disclosure, intigriti] - source: security/showpad-domain-security.yml kind: caa-iodef detail: '0 iodef "mailto:security@showpad.com"' security_txt: served: false note: >- No /.well-known/security.txt is served on showpad.com, www.showpad.com or developer.showpad.com. status.showpad.com does return one, but it is Atlassian Statuspage's document (Contact: https://www.atlassian.com/trust/security/...), not Showpad's — see well-known/showpad-well-known.yml.