DocSend · Vulnerability Disclosure

Docsend Vulnerability Disclosure

Vulnerability disclosure

DocSend runs a coordinated vulnerability disclosure program on Intigriti. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyEnterpriseDocument SharingSales EnablementAnalyticsData RoomE-SignatureMCPDropbox
Program: Intigriti security.txt present

Disclosure Policy

Policy

Security Contact

Contact
bugbounty@dropbox.com

Source

Vulnerability Disclosure

docsend-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.dropbox.com/.well-known/security.txt
policy:
- https://app.intigriti.com/programs/dropbox/dropbox-vdp
bug_bounty:
- https://app.intigriti.com/programs/dropbox/dropbox
acknowledgements:
- https://app.intigriti.com/programs/dropbox/dropbox/leaderboard
contact:
- bugbounty@dropbox.com
abuse_contact:
- abuse@dropbox.com
platform: Intigriti
ownership_note: >-
  The disclosure program that covers DocSend is Dropbox's, not one served on
  docsend.com — https://docsend.com/.well-known/security.txt returns HTTP 404 and there is
  no disclosure page on the DocSend domain. This is a parent-brand case, the same shape as
  Workfront reporting to adobe.com: DocSend has been a Dropbox product since 2021, and
  DocSend's own trust center at www.docsend.com/trust-center/security lists "Bug Bounty"
  under App Security as part of the security posture it publishes for the DocSend service.
  The reachable program is therefore Dropbox's Intigriti program, reported here with that
  provenance stated rather than presented as a DocSend-served policy.
gap:
  docsend_security_txt: 404
  note: >-
    DocSend serves no RFC 9116 security.txt of its own on docsend.com or mcp.docsend.com. A
    one-line security.txt on docsend.com pointing at the Dropbox Intigriti program would
    close this — currently a researcher who finds a bug in the DocSend MCP endpoint has no
    machine-readable route to report it from the host they found it on.
evidence:
- source: https://www.dropbox.com/.well-known/security.txt
  status: 200
  kind: security.txt
  file: well-known/dropbox-security.txt
- source: https://docsend.com/.well-known/security.txt
  status: 404
  kind: security.txt
- source: https://mcp.docsend.com/.well-known/security.txt
  status: 404
  kind: security.txt
- source: https://www.docsend.com/trust-center/security
  status: 200
  kind: trust-center
  keywords: [bug bounty, vulnerability management, app security, pentest reports]

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/docsend-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.