DebtBook · Vulnerability Disclosure

Debtbook Vulnerability Disclosure

Vulnerability disclosure

DebtBook runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyTreasury ManagementGovernmentPublic FinanceDebt ManagementCash ManagementAccountingLease AccountingInvestment ManagementNonprofitHigher EducationHealthcareSaaS
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
https://www.debtbook.com/security
Contact
hello@debtbook.com

Source

Vulnerability Disclosure

debtbook-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-04'
method: searched
source: https://www.debtbook.com/vdp
probe: true
program:
  name: DebtBook Vulnerability Disclosure Program
  url: https://www.debtbook.com/vdp
  type: responsible-disclosure
  bug_bounty: false
  monetary_rewards: false
  platform: none
  intake: web form linked from the DebtBook security page (no third-party platform
    such as HackerOne, Bugcrowd or Intigriti is used)
policy:
- https://www.debtbook.com/vdp
contact:
- https://www.debtbook.com/security
- hello@debtbook.com
scope:
  in_scope:
  - app.debtbook.com
  - sources.debtbook.com
  - uat.debtbook.com
  out_of_scope:
  - the third-party Intercom messaging script embedded in the application
  requirements:
  - Researchers must include the token "(db_vdp)" in the HTTP User-Agent header so
    security testing traffic can be distinguished from real user traffic.
  - No unauthorized access, data exfiltration, or service disruption.
safe_harbor:
  offered: true
  covers:
  - Computer Fraud and Abuse Act (CFAA)
  - Digital Millennium Copyright Act (DMCA)
  condition: good-faith research that follows the published program guidelines
sla:
  first_response: 5 business days
  time_to_triage: 10 business days
  resolution: dependent on severity and complexity
security_txt:
  published: false
  note: no /.well-known/security.txt is served on debtbook.com, www.debtbook.com or
    app.debtbook.com (RFC 9116 gap — the VDP exists but is not machine-discoverable)
evidence:
- source: https://www.debtbook.com/vdp
  kind: vulnerability-disclosure-policy
  http_status: 200
  fetched: '2026-08-04'
- source: https://www.debtbook.com/security
  kind: security-page
  http_status: 200
  fetched: '2026-08-04'
x-evidence:
  fetched: '2026-08-04'
  note: the mechanical probe (probe-security-programs.py) returned no hit because the
    policy lives at the non-standard path /vdp and the HubSpot-rendered /security page
    did not meet the keyword threshold; both pages were then fetched and read directly.