generated: '2026-08-27' method: searched source: https://www.silentpush.com/responsible-disclosure/ program: published: true name: Vulnerability Disclosure Policy url: https://www.silentpush.com/responsible-disclosure/ http_status: 200 type: coordinated-disclosure bug_bounty: false bug_bounty_note: >- No bug bounty program and no HackerOne, Bugcrowd or Intigriti presence found. The policy offers no monetary reward. contact: email: security@silentpush.com email_source: >- decoded from the Cloudflare email-obfuscation payload on https://www.silentpush.com/responsible-disclosure/ (the address is not served as plain text) pgp_key: null security_txt: null security_txt_note: >- Silent Push serves no RFC 9116 /.well-known/security.txt on any host - see well-known/silent-push-well-known.yml. scope: in_scope: - https://app.silentpush.com - '*.silentpush.com' out_of_scope: - all other systems and services (explicitly excluded by the policy) commitments: acknowledgement: within three business days validation: 'timely validation of submissions' remediation: 'corrective action implemented where appropriate' researcher_notification: 'researchers informed of vulnerability disposition' embargo: >- researchers must refrain from public disclosure for 90 calendar days after receiving acknowledgement of their report safe_harbor: offered: true text: >- "If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized... and we will not recommend or pursue legal action related to your research." x-evidence: - url: https://www.silentpush.com/responsible-disclosure/ http_status: 200 fetched: '2026-08-27'