Conversica · Vulnerability Disclosure

Conversica Vulnerability Disclosure

Vulnerability disclosure

Conversica publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyArtificial IntelligenceConversational AIAI AgentsSalesMarketingLead ManagementCRMMarketing AutomationCustomer EngagementMessagingSMSEmailChatAutomotiveHigher EducationWebhooks
Program:

Disclosure Policy

Policy

Security Contact

Contact
security@conversica.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-01'
method: searched
probe: true
source: https://www.conversica.com/legal-info/responsible-disclosure-policy
policy:
- https://www.conversica.com/legal-info/responsible-disclosure-policy
contact:
- security@conversica.com
program:
  name: Conversica Responsible Disclosure Policy
  bug_bounty: false
  bug_bounty_platform: null
  safe_harbor: true
  safe_harbor_note: >-
    Conversica states that if a researcher makes a good faith effort to comply with the
    policy during security research, Conversica will consider the research authorized and
    will not pursue legal action related to compliant research activity.
  embargo_days: 90
  embargo_note: >-
    Researchers are asked to refrain from sharing information about a discovered
    vulnerability for 90 calendar days after receiving Conversica's acknowledgement of
    receipt.
  hall_of_fame: false
  hall_of_fame_note: The RDP Program Acknowledgments section currently lists "none".
  pgp_supported: false
  pgp_note: The policy states PGP-encrypted email is not supported at this time.
scope:
  in_scope:
  - https://my.conversica.com
  - https://integrations-api.conversica.com
  in_scope_note: Subdomains of the listed systems are in scope unless explicitly excluded.
  out_of_scope:
  - Third-party vendor systems
security_txt:
  published: false
  probed:
  - url: https://www.conversica.com/.well-known/security.txt
    http_status: 404
  - url: https://conversica.com/.well-known/security.txt
    http_status: 404
  - url: https://integrations-api.conversica.com/.well-known/security.txt
    http_status: 404
  - url: https://my.conversica.com/.well-known/security.txt
    http_status: 404
  note: >-
    Conversica publishes a real disclosure policy page but no RFC 9116 security.txt at any
    probed host, so the policy is discoverable to humans and not to machines.
evidence:
- source: https://www.conversica.com/legal-info/responsible-disclosure-policy
  kind: disclosure-policy-page
  http_status: 200
  keywords: [responsible disclosure, security@conversica.com, safe harbor, good faith]
x-evidence:
  fetched: '2026-08-01'
  url: https://www.conversica.com/legal-info/responsible-disclosure-policy
  http_status: 200