generated: '2026-08-28' method: searched source: https://www.connectwise.com/company/trust/security/vulnerability-disclosure-policy note: >- SkyKick serves no security.txt of its own — /.well-known/security.txt returned 404 on skykick.com and on every ConnectWise Cloud Services host (probed 2026-08-28). The disclosure program that covers the former SkyKick services is the ConnectWise one, published in full and open to anonymous reports. program: present: true type: coordinated vulnerability disclosure bug_bounty: false bounty_note: >- "any reward is at the discretion of ConnectWise" — a discretionary acknowledgement, not a bounty program. No HackerOne or Bugcrowd listing exists (hackerone.com/connectwise and bugcrowd.com/connectwise both returned 404, probed 2026-08-28). policy_url: https://www.connectwise.com/company/trust/security/vulnerability-disclosure-policy probed: '2026-08-28' http_status: 200 reporting: email: disclosure@connectwise.com anonymous_reports_accepted: true acknowledgement_sla: 3 business days (when contact information is provided) incident_hotline: name: Partner InfoSec Hotline phone: 1-888-WISE911 email: securityincident@connectwise.com purpose: active, urgent security incidents safe_harbor: present: true text: >- "If you make a good faith effort to comply with this policy during your security research or discovery, we will consider your research to be authorized... ConnectWise will not recommend or pursue legal action related to your research." required_report_contents: - Clear description of the vulnerability and its potential impact - Product, version and configuration of any software or hardware impacted - Step-by-step reproduction instructions - A proof-of-concept - Suggested mitigation or remediation publication: advisories: url: https://www.connectwise.com/company/trust/advisories rss: https://www.connectwise.com/company/trust/advisories/rss probed: '2026-08-28' http_status: 200 security_bulletins: url: https://www.connectwise.com/company/trust/security-bulletins rss: https://www.connectwise.com/company/trust/security-bulletins/rss probed: '2026-08-28' http_status: 200 disclosure_repository: url: https://github.com/ConnectWise-Advisories/Disclosures probed: '2026-08-28' http_status: 200 note: A public GitHub repository of ConnectWise-issued disclosures. security_txt: present: false probed: '2026-08-28' hosts_probed: - host: skykick.com status: 404 - host: apis.cloudservices.connectwise.com status: 404 - host: skykick.developer.azure-api.net status: 404 - host: developers.cloudservices.connectwise.com status: 404 recommendation: >- An RFC 9116 security.txt at apis.cloudservices.connectwise.com pointing at the existing policy URL and disclosure@connectwise.com would make this program machine-discoverable; today it is only findable by reading the Trust Center.