Augmentt · Vulnerability Disclosure

Augmentt Vulnerability Disclosure

Vulnerability disclosure

Augmentt runs a coordinated vulnerability disclosure program on Hackerone.

MSPMicrosoft 365SaaS ManagementSaaS SecurityShadow ITSecurity PostureComplianceLicense ManagementMulti-TenantReporting
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-14'
method: searched
probe: true
source: https://www.augmentt.com/responsible-disclosure-policy/
provider: Augmentt
providerId: augmentt
# 2026-09-14: the previous version of this file cited
# https://www.augmentt.com/vulnerability-disclosure as its evidence. That URL is a SOFT-404 — it
# returns HTTP 200 with the WordPress "404 - Page not found - Augmentt" template. The real policy is
# at /responsible-disclosure-policy/ and is captured below.
published: true
policy_url: https://www.augmentt.com/responsible-disclosure-policy/
policy_status: 200
checked: '2026-09-14'
title: Responsible Disclosure Policy
submission:
  channel: email
  contact: security@augmentt.com
  contact_note: >-
    The address is obfuscated on the policy page by the site's email-protection script; the
    submission instruction itself ("All discovered vulnerabilities shall be submitted to <email>") is
    verbatim. security@augmentt.com is corroborated independently by the augmentt.com CAA record,
    which carries `0 iodef "mailto:security@augmentt.com"` (probed 2026-09-14,
    security/augmentt-domain-security.yml).
  acknowledgement_sla: 3-5 business days
bounty:
  offered: true
  platform: none
  self_hosted: true
  amounts_published: false
  detail: >-
    Augmentt pays a monetary bounty for Medium and High risk disclosures. Payout amounts are not
    disclosed. Eligibility is at Augmentt's discretion based on impact, risk, data exposure, ease of
    exploitation and report quality. Duplicates are awarded to the first submitter.
  no_platform_note: >-
    No HackerOne, Bugcrowd or Intigriti program was found for Augmentt; the program is run directly
    over email.
risk_model:
  methodology: OWASP Risk Rating Methodology
  factors: [impact, likelihood]
  scale: 1 (very low) to 5 (very high)
  formula: risk = impact * likelihood
  severity_levels:
    - level: High
      reward: highest tier
    - level: Moderate
      reward: regular reward rate
    - level: Low
      reward: discretionary reward rate
    - level: Informational
      reward: none — acknowledged but not assigned a risk level
exclusions:
  - Physical testing, such as office access (open doors, tailgating)
  - Findings derived primarily from social engineering (phishing, vishing)
  - Functional, UI and UX bugs and spelling mistakes
  - Denial of service (DoS/DDoS)
  - Already publicly disclosed vulnerabilities
  - Testing that caused an incident to Augmentt services or infrastructure
  - Informational or low business-impact findings
security_txt:
  published: false
  probed:
    - url: https://www.augmentt.com/.well-known/security.txt
      status: 404
    - url: https://app.augmentt.com/.well-known/security.txt
      status: 200
      note: SPA catch-all returning HTML, not an RFC 9116 document.
  note: >-
    A real policy exists but is not machine-discoverable. Publishing an RFC 9116 security.txt with
    Policy and Contact fields pointing at /responsible-disclosure-policy/ would close the gap.
evidence:
  - url: https://www.augmentt.com/responsible-disclosure-policy/
    status: 200
    kind: disclosure policy
  - url: https://www.augmentt.com/vulnerability-disclosure
    status: 200
    kind: soft-404
    note: Returns the site 404 template. Superseded; do not cite.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/augmentt-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.