generated: '2026-08-27' method: searched source: https://www.sigmacomputing.com/product/vdp + https://security.sigmacomputing.com/ program: published: true type: vulnerability disclosure policy (self-managed) url: https://www.sigmacomputing.com/product/vdp probed_status: 200 title: Sigma Vulnerability Disclosure Policy bug_bounty: exists: advertised platform: null note: The site footer labels the link "Bug Bounty" but the page it opens is a Vulnerability Disclosure Policy with no stated bounty, reward table, or third-party platform (no HackerOne, Bugcrowd or Intigriti presence found). Recorded as a VDP, not a bounty — the label and the page disagree. contact: email: security@sigmacomputing.com source: https://security.sigmacomputing.com/ (SafeBase trust center) secondary: GRC@sigmacomputing.com security_txt: served: false probed: - https://www.sigmacomputing.com/.well-known/security.txt - https://help.sigmacomputing.com/.well-known/security.txt - https://api.sigmacomputing.com/.well-known/security.txt - https://aws-api.sigmacomputing.com/.well-known/security.txt status: 404 gap: A four-line RFC 9116 security.txt naming the existing policy URL and security@sigmacomputing.com would make an already-real program machine-discoverable. This is the cheapest single improvement available to Sigma in this whole profile. policy: scope: All products, services and infrastructure developed, managed and maintained by Sigma Computing. safe_harbour_stated: false expectations: - Do not violate the privacy of other users, destroy data, or disrupt services. - Report promptly with enough detail to reproduce. - Do not disclose publicly or to third parties before Sigma has responded. - Do not degrade Sigma products or services. - Do not access, modify or destroy customer data. - Comply with applicable law. - Stop testing and notify Sigma immediately once a vulnerability is established or sensitive data is encountered. out_of_scope: - Physical attacks against infrastructure, facilities or offices - Social engineering of employees, contractors or vendors - Denial of service or anything disrupting the service - Findings from a compromised account - Raw scanner output - User interface bugs anti_phishing_notice: Sigma states it will never request passwords or financial details through unsolicited communications. related_policies: - name: Security policy url: https://www.sigmacomputing.com/legal/security-policy status: 200 - name: Data processing addendum url: https://www.sigmacomputing.com/legal/dpa - name: Subprocessors url: https://www.sigmacomputing.com/legal/subprocessors status: 200