generated: '2026-08-27' method: searched source: >- https://github.com/sift-stack/sift/blob/main/SECURITY.md (present in the repository tarball fetched 2026-08-27); /.well-known/security.txt probed and 404 on both public hosts. name: Sift vulnerability disclosure published: true channel: repository-security-policy policy_url: https://github.com/sift-stack/sift/blob/main/SECURITY.md report_url: https://customer.support.siftstack.com/servicedesk/customer/portal/2/group/2/create/9 security_txt: false bug_bounty: program: false platforms_checked: [hackerone, bugcrowd, intigriti] note: No bug bounty or coordinated-disclosure program was found. safe_harbor: false pgp_key: false disclosure_policy: coordinated: true embargo_requested: true quote: '"Please take care not to publicize this report as it may put other users at risk."' verbatim_policy: | # SECURITY POLICY ## Reporting a Vulnerability If you come across security vulnerability please do the following: 1. Notify the Sift team immediately through the shared Slack channels. 2. File a bug report at [this link](https://customer.support.siftstack.com/servicedesk/customer/portal/2/group/2/create/9). Please take care not to publicize this report as it may put other users at risk. gaps: - 'The policy is written for CUSTOMERS, not for the public. Step one is "notify the Sift team immediately through the shared Slack channels" — a channel only an existing customer has. A researcher with no commercial relationship has one usable route, the Jira Service Management portal.' - 'No /.well-known/security.txt on docs.siftstack.com or www.siftstack.com (both 404), so an automated scanner finds no disclosure route at all — the policy is discoverable only by reading a file in a GitHub repository.' - 'No security@ address, no PGP key, no safe-harbor statement, no stated response SLA.' - 'For a vendor holding ITAR-controlled defense telemetry, this is the widest gap in an otherwise strong security posture, and it is cheap to close: a two-line security.txt on both hosts pointing at the existing portal.'