Bigeye · Vulnerability Disclosure

Bigeye Vulnerability Disclosure

Vulnerability disclosure

Bigeye runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyData ObservabilityData QualityData LineageData GovernanceMetadata ManagementData CatalogSensitive Data DiscoveryMonitoringAnalyticsAI TrustSnowflakeDatabricks
Program: Hackerone

Disclosure Policy

Security Contact

Contact
security@bigeye.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-02'
method: searched
probe: true
source: https://www.bigeye.com/platform/security
url: https://www.bigeye.com/platform/security
contact:
- security@bigeye.com
policy: []
bug_bounty:
  program: null
  platform: null
  note: >-
    No bug bounty program was found on HackerOne, Bugcrowd or Intigriti, and
    none is referenced on Bigeye's site or documentation.
formal_disclosure_policy: false
formal_disclosure_policy_note: >-
  Bigeye publishes a named security contact and describes its vulnerability
  management practices, but does not publish a formal responsible-disclosure or
  coordinated-vulnerability-disclosure policy with scope, safe harbour and
  response commitments. Recorded honestly: a reachable security contact exists,
  a published VDP does not.
security_txt:
  present: false
  probed:
  - {url: 'https://www.bigeye.com/.well-known/security.txt', status: 404}
  - {url: 'https://docs.bigeye.com/.well-known/security.txt', status: 404}
  - {url: 'https://mcpgateway.bigeye.com/.well-known/security.txt', status: 404}
  - {url: 'https://app.bigeye.com/.well-known/security.txt', status: 200 (rejected
      — SPA HTML catch-all, not RFC 9116 text)}
  recommendation: Publishing an RFC 9116 /.well-known/security.txt pointing at security@bigeye.com
    would be a one-file fix.
practices_published:
  source: https://docs.bigeye.com/docs/security-and-compliance
  items:
  - {practice: vulnerability scanning, detail: Code review and dependency vulnerability
      scans as part of the software engineering process.}
  - {practice: penetration testing, detail: Annual third-party penetration test over
      the application layers; reports available on demand.}
  - {practice: web application firewall, detail: AWS WAF Security Automation.}
  - {practice: security incident notification, detail: Customers notified without undue
      delay by email, or by phone if email is unavailable.}
  - {practice: security training, detail: Privacy and security training at onboarding
      and annually thereafter, with electronic acknowledgement.}
  - {practice: access restriction, detail: Only the Information Security Team and CTO
      can access customer data during incident response.}
evidence:
- source: https://www.bigeye.com/platform/security
  kind: security page
  quote: Security inquiries — Have a question about our security practices? Reach out
    to our security team at security@bigeye.com
  fetched: '2026-08-02'
  http_status: 200
- source: https://docs.bigeye.com/docs/security-and-compliance
  kind: security practices documentation
  fetched: '2026-08-02'
  http_status: 200