Comulate · Vulnerability Disclosure

Comulate Vulnerability Disclosure

Vulnerability disclosure

Comulate runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyInsuranceInsurTechAccountingReconciliationAutomationRevenue IntelligenceFintechInsurance Brokers
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@comulate.com

Source

Vulnerability Disclosure

comulate-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://comulate.com/security
contact:
- security@comulate.com
policy:
- https://comulate.com/security
formal_policy: false
bug_bounty: null
security_txt: false
note: >-
  Comulate names a security contact and invites reports on its security page, verbatim:
  "If you have any questions, comments or concerns or if you wish to report a potential
  security issue, please contact security@comulate.com." There is NO formal responsible-
  disclosure or vulnerability-disclosure policy document, no safe-harbor language, and no
  bug bounty program (no HackerOne / Bugcrowd / Intigriti listing found). No
  /.well-known/security.txt is served on any Comulate host — see
  well-known/comulate-well-known.yml. This is a reporting channel, not a disclosure
  program; recorded at that strength.
evidence:
- source: https://comulate.com/security
  kind: disclosure page
  status: 200
  keywords:
  - vulnerability
  - security issue
  - security@
- source: https://comulate.com/.well-known/security.txt
  kind: security.txt
  status: 404
  finding: not served