generated: '2026-09-04' method: searched source: https://virtualitics.com/disclosures/ checked: '2026-09-04' found: true program: name: Vulnerability Reporting Policy url: https://virtualitics.com/disclosures/ kind: coordinated vulnerability disclosure (no bounty) bug_bounty: false bounty_note: >- Explicit: "Do not request compensation. We do not offer any cash compensation or incentives in return for security reports." No HackerOne, Bugcrowd or Intigriti program was found. safe_harbor: true safe_harbor_summary: >- Research under the policy is treated as authorized with respect to anti-hacking and anti-circumvention law; Virtualitics waives the Terms of Service / Acceptable Use restrictions that would interfere with security research on a limited basis, and commits to stating that a complying researcher acted in compliance if a third party initiates legal action. scope: Any digital assets owned, operated, or maintained by Virtualitics. out_of_scope: Assets or equipment not owned by parties participating in the policy. disclosure_window: at least 90 days from the initial report before public disclosure commitments: - Respond to the report promptly and work with the reporter to understand and validate it - Keep the reporter informed of progress - Remediate in a timely manner within operational constraints - Extend safe harbor expectations: - Report promptly - Avoid privacy violations, service disruption, data destruction - Use only the official channel to discuss vulnerability information - Minimize data access; stop and report immediately on encountering PII/PHI/card/proprietary data - Interact only with test accounts you own or are permitted to use contact: channel: email address: security@virtualitics.com source: https://virtualitics.com/disclosures/ note: >- Published on the disclosures page behind Cloudflare email obfuscation (data-cfemail); decoded verbatim as "security@Virtualitics.com" and normalized to lowercase here. security_txt: present: false probed: - url: https://virtualitics.com/.well-known/security.txt status: 404 - url: https://docs.virtualitics.com/.well-known/security.txt status: 404 - url: https://sdk.virtualitics.com/.well-known/security.txt status: 404 - url: https://accounts.virtualitics.com/.well-known/security.txt status: 500 note: >- Virtualitics has a real, well-written disclosure policy and a security@ address but publishes no RFC 9116 security.txt. Adding one — Contact, Policy, Preferred-Languages, Expires — would make an existing program machine-discoverable at zero cost. This is the single cheapest security-surface improvement available to this provider. findability_defect: url: https://virtualitics.com/vulnerability-reporting-policy/ status: 200 finding: >- A page whose