generated: '2026-08-29' method: searched source: https://www.strivacity.com/report-a-security-issue url: https://www.strivacity.com/report-a-security-issue http_status: 200 program: type: responsible-disclosure bug_bounty: false paid: false safe_harbor_stated: false acknowledgement: >- "we will give you full public acknowledgement in helping improve the security of our offerings" contact: email: security@strivacity.com pgp: true pgp_fingerprint: CB4C 7C3D 3586 425B F7FB 4B01 500D 02FC AFDA 582F policy: coordinated_disclosure: >- Strivacity asks researchers to wait until the issue is acknowledged and fixed, and to give Strivacity the opportunity to ship a fix to its customers, before any public disclosure. severity_scoring: NIST CVSS (requested, not required) required_report_contents: - detailed steps to reproduce - exactly where in the process the vulnerability is found - CVSS classification (optional) out_of_scope: - clickjacking-only issues - missing HTTP security headers - non-200 HTTP status pages (404 etc.) - OPTIONS / TRACE HTTP methods enabled - missing X-Content-Type-Options / anti-MIME-sniffing header - username, email or phone enumeration via login or forgotten-password error messages - verbose error messages and stack traces - disclosure of known public files or directories (robots.txt) - CSRF on forms available to anonymous visitors - logout CSRF - 'remember my device / remember my username functionality' - missing Secure / HttpOnly cookie flags - missing security speedbump on outbound links - SSL attacks (BEAST, BREACH, renegotiation), missing forward secrecy, weak cipher suites security_txt: served: false probed: - url: https://www.strivacity.com/.well-known/security.txt status: 404 - url: https://docs.strivacity.com/.well-known/security.txt status: 404 note: >- A published responsible-disclosure policy exists, but it is not machine-discoverable — no RFC 9116 /.well-known/security.txt is served on any Strivacity host. Adding one that points Policy: at https://www.strivacity.com/report-a-security-issue and Contact: at mailto:security@strivacity.com would make an existing program discoverable to automated scanners at no policy cost.