Drip · Vulnerability Disclosure
Drip Vulnerability Disclosure
Vulnerability disclosure
Drip publishes a machine-readable vulnerability disclosure contact via RFC 9116 security.txt, served from both the API host and the application host, and clearsigned with a PGP key it also publishes. That is a real disclosure surface — but a thin and stale one: there is no Policy field pointing at disclosure terms, no Acknowledgments, no bug bounty program, and crucially no `Expires` field, which RFC 9116 makes REQUIRED. The PGP signature timestamp puts the document's last signing in 2020.
Drip publishes a vulnerability disclosure policy for reporting security issues.
Email MarketingMarketing AutomationE-CommerceCustomer EngagementCampaignsWorkflows
Program: