Boxabl · Vulnerability Disclosure

Boxabl Vulnerability Disclosure

Vulnerability disclosure

BOXABL runs a real, publicly documented responsible-disclosure ("bug bounty") program. It is discoverable the correct way: an RFC 9116 security.txt at https://www.boxabl.com/.well-known/security.txt whose Contact field resolves to a published policy PDF. The policy defines scope, out-of-scope classes, rules of engagement, a safe-harbour clause, the submission channel and a discretionary CVSS-linked compensation model. This is notably more mature security-disclosure posture than most companies in the catalog that publish no API at all. Detail below was read from the policy PDF itself; the mechanical probe (0-working/probe-security-programs.py) independently confirmed the security.txt Contact hit.

Boxabl publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyConstructionManufacturingHousingReal EstateModular HomesPrefabricated ConstructionAccessory Dwelling UnitsNasdaqConsumer Products
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
bugs@boxabl.com
Contact
https://gcdn.boxabl.com/documents/bugbounty/Boxabl%20Policy.pdf

Source

Vulnerability Disclosure

boxabl-vulnerability-disclosure.yml Raw ↑
generated: '2026-07-31'
method: searched
probe: true
source: https://www.boxabl.com/.well-known/security.txt
description: >-
  BOXABL runs a real, publicly documented responsible-disclosure ("bug bounty")
  program. It is discoverable the correct way: an RFC 9116 security.txt at
  https://www.boxabl.com/.well-known/security.txt whose Contact field resolves
  to a published policy PDF. The policy defines scope, out-of-scope classes,
  rules of engagement, a safe-harbour clause, the submission channel and a
  discretionary CVSS-linked compensation model. This is notably more mature
  security-disclosure posture than most companies in the catalog that publish no
  API at all. Detail below was read from the policy PDF itself; the mechanical
  probe (0-working/probe-security-programs.py) independently confirmed the
  security.txt Contact hit.
policy:
- https://gcdn.boxabl.com/documents/bugbounty/Boxabl%20Policy.pdf
contact:
- bugs@boxabl.com
- https://gcdn.boxabl.com/documents/bugbounty/Boxabl%20Policy.pdf
program:
  type: self-hosted
  platform: null
  bounty: true
  bounty_model: >-
    Discretionary compensation determined by BOXABL, weighted by a CVSS-linked
    severity formula, report quality, internal risk assessment, prior-disclosure
    status (paid once per issue) and applicable sanctions legislation.
  safe_harbor: true
  safe_harbor_note: >-
    BOXABL states it will not pursue legal action against researchers who submit
    reports covering in-scope products through the approved channel and who
    follow the stated rules of engagement.
  coordinated_disclosure: true
  disclosure_note: >-
    Researchers are asked to refrain from public disclosure prior to a mutually
    agreed date; BOXABL commits to a timely initial response, open dialog on
    remediation timelines, and notification when remediation is complete.
scope:
  in_scope:
  - www.boxabl.com (the BOXABL marketing site)
  - Any publicly exposed infrastructure element supporting BOXABL product or business operations
  out_of_scope:
  - Third-party business applications leveraged by BOXABL
  - Non-production environments, unless the vulnerability directly impacts production
  excluded_classes:
  - Configuration/best-practice findings (SPF/DMARC, CORS, security headers, weak TLS ciphers)
  - Denial of service
  - Information disclosure such as file paths, absent sensitive-data impact
  - Clickjacking
  - Email and account policy issues (reset method, password complexity)
  - Theoretical or self-XSS without demonstrated exploitability
  excluded_note: >-
    The excluded classes are in scope only where the implementation results in
    data leakage or account takeover.
  submission_preferences:
  - Written in English where possible
  - Include proof-of-concept code to aid triage
  - Include identification method, suggested impact rating and suggested remediation
  - More than raw automated scanner output
  - State any public-disclosure intentions or timelines
evidence:
- {source: 'well-known/boxabl-security.txt', kind: security.txt, field: Contact}
- {source: 'https://gcdn.boxabl.com/documents/bugbounty/Boxabl%20Policy.pdf', kind: disclosure-policy, http_status: 200, content_type: application/pdf}
probes:
- {url: 'https://www.boxabl.com/.well-known/security.txt', status: 200}
- {url: 'https://gcdn.boxabl.com/documents/bugbounty/Boxabl%20Policy.pdf', status: 200}
- {url: 'https://www.boxabl.com/security', status: 404}
- {url: 'https://trust.boxabl.com/', status: 0, note: host does not resolve}
- {url: 'https://security.boxabl.com/', status: 0, note: host does not resolve}
x-evidence:
  fetched: '2026-07-31'
  url: https://www.boxabl.com/.well-known/security.txt
  http_status: 200
  content_type: text/plain; charset=utf-8