Brandfolder · Vulnerability Disclosure

Brandfolder Vulnerability Disclosure

Vulnerability disclosure

Brandfolder publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Digital Asset ManagementDAMBrand ManagementAssetsMediaCollectionSmartsheet
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@smartsheet.com
Contact
https://www.smartsheet.com/legal/bugbounty

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.smartsheet.com/.well-known/security.txt
url: https://www.smartsheet.com/legal/bugbounty
policy:
  - https://www.smartsheet.com/legal/bugbounty
contact:
  - security@smartsheet.com
  - https://www.smartsheet.com/legal/bugbounty
security_txt:
  served_on_api_host: false
  host: www.smartsheet.com
  file: well-known/brandfolder-security.txt
  canonical: https://www.smartsheet.com/.well-known/security.txt
  expires: '2026-07-01T04:00:00.000Z'
  expired_at_probe: true
  preferred_languages: en
attribution_note: >
  Brandfolder does not run its own disclosure program and serves no security.txt
  on brandfolder.com (404). The applicable program is the parent company's:
  Brandfolder has been a Smartsheet company since August 2020, and
  brandfolder.com's own CAA record carries
  `0 iodef "mailto:security@smartsheet.com"` - the provider's own DNS naming
  Smartsheet security as the reporting channel for this domain. That is why the
  Smartsheet researcher portal is recorded here rather than treated as a
  different company's program.
evidence:
  - source: https://www.smartsheet.com/.well-known/security.txt
    kind: security.txt
    status: 200
  - source: https://www.smartsheet.com/legal/bugbounty
    kind: researcher-portal
    status: 200
  - source: https://brandfolder.com/.well-known/security.txt
    kind: security.txt
    status: 404
  - source: brandfolder.com CAA record
    kind: dns
    value: '0 iodef "mailto:security@smartsheet.com"'
gaps:
  - The published security.txt Expires field is 2026-07-01 - the document was expired when probed on 2026-08-13.
  - No security.txt on the API host (brandfolder.com) or the docs host (developers.smartsheet.com).