8x8 · Vulnerability Disclosure

8X8 Vulnerability Disclosure

Vulnerability disclosure

8x8 runs a coordinated vulnerability disclosure program on Hackerone.

TelecommunicationsUnited StatesCPaaSUCaaSCCaaSContact CenterMessagingSMSVoiceVideoIdentity VerificationWebhooksCloud Communications
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-25'
method: searched
probe: true
source: https://cpaas.8x8.com/en/security/

program:
  runs_vdp: true
  runs_bug_bounty: true
  platform: HackerOne
  statement: >-
    "8x8 runs responsible disclosure and incentivized bounty programs through HackerOne
    to allow anyone to report vulnerabilities. With this National Institute of Standards
    and Technology best-practice responsible disclosure program, we have a well-defined
    process for finding and fixing vulnerabilities — before they could be exploited."

policy:
- url: https://hackerone.com/8x8-bounty
  name: 8x8 Bug Bounty Program (HackerOne)
  status: 200
- url: https://cpaas.8x8.com/en/security/
  name: 8x8 CPaaS Security
  status: 200
- url: https://www.8x8.com/products/apis/security
  name: Security for 8x8 Communication APIs
  status: 429
  status_note: www.8x8.com sits behind a Vercel security checkpoint that returns 429 to
    automated clients; the page is real and is linked from 8x8's own developer docs
    (developer.8x8.com/connect/docs/security-1).
- url: https://www.8x8.com/why-8x8/security-and-compliance
  name: 8x8 Security & Global Compliance Standards
  status: 429

contact: []
contact_note: >-
  8x8's CPaaS security page publishes a security contact address behind Cloudflare email
  obfuscation, so the literal address was not recovered and is not guessed here. Reports
  are accepted through the HackerOne programs above.

security_txt:
  published: false
  probed:
  - {host: www.8x8.com, path: /.well-known/security.txt, status: 429}
  - {host: developer.8x8.com, path: /.well-known/security.txt, status: 404}
  - {host: api.8x8.com, path: /.well-known/security.txt, status: 404}
  - {host: sms.8x8.com, path: /.well-known/security.txt, status: 404}
  - {host: voice.8x8.com, path: /.well-known/security.txt, status: 404}
  note: No RFC 9116 security.txt was served from any 8x8 API or developer host. The
    disclosure program is real but is not machine-discoverable at /.well-known/security.txt.

disclosed_reports_public: true
disclosed_reports_note: 8x8 has publicly disclosed HackerOne reports (e.g. hackerone.com/reports/504122,
  hackerone.com/reports/1391576), evidence the program is operated rather than nominal.

evidence:
- source: https://cpaas.8x8.com/en/security/
  kind: vendor security page
  keywords: [responsible disclosure, bounty, HackerOne, NIST]
- source: https://hackerone.com/8x8-bounty
  kind: bug bounty program
  status: 200