generated: '2026-06-20' method: searched probe: true source: >- https://www.hashicorp.com/en/trust/security/vulnerability-management, https://www.hashicorp.com/en/trust/security, https://support.hashicorp.com/hc/en-us/articles/1500000026401-Reporting-HashiCorp-security-vulnerabilities policy: - https://www.hashicorp.com/en/trust/security/vulnerability-management contact: - security@hashicorp.com bug_bounty: false bug_bounty_note: >- HashiCorp does not operate a public bug bounty program and does not offer monetary rewards; reporters may be acknowledged in product security bulletins. disclosure_process: >- Report vulnerabilities by email to security@hashicorp.com. HashiCorp replies shortly after receipt and provides periodic updates on response and remediation status. PGP key and reporting guidance are published on the vulnerability management page. evidence: - {source: https://www.hashicorp.com/en/trust/security/vulnerability-management, kind: disclosure-page} - {source: https://www.hashicorp.com/en/trust/security, kind: security-page, detail: "security@hashicorp.com contact"}