eSentire · Vulnerability Disclosure

Esentire Vulnerability Disclosure

Vulnerability disclosure

eSentire publishes a named security contact but not a vulnerability disclosure policy. The contact is genuine and provider-published — security@esentire.com, attributed on eSentire's own trust page to the "Office of the CISO / Governance Risk and Compliance Team". That is the entire published surface. There is no disclosure policy page, no safe-harbour statement, no reporting SLA, no PGP key, no RFC 9116 security.txt on any eSentire host, and no bug bounty program on HackerOne, Bugcrowd or Intigriti. For an MDR vendor whose own research unit publishes security advisories about other people's software, the absence of an inbound disclosure policy is a notable asymmetry.

eSentire runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanySecurityCybersecurityManaged Detection and ResponseThreat IntelligenceIncident ResponseMCPAgentsAuthenticationSoftware-as-a-Service
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy

Security Contact

Contact
attributed_toOffice of the CISO — Governance Risk and Compliance Team
Contact
emailsecurity@esentire.com
Contact
published_athttps://trust.esentire.com/
Contact
verifiedtrue

Source

Vulnerability Disclosure

esentire-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-12'
method: searched
source: https://trust.esentire.com/api/trustpage/public/v1/
name: eSentire security disclosure
description: >-
  eSentire publishes a named security contact but not a vulnerability disclosure
  policy. The contact is genuine and provider-published — security@esentire.com,
  attributed on eSentire's own trust page to the "Office of the CISO / Governance
  Risk and Compliance Team". That is the entire published surface. There is no
  disclosure policy page, no safe-harbour statement, no reporting SLA, no PGP key,
  no RFC 9116 security.txt on any eSentire host, and no bug bounty program on
  HackerOne, Bugcrowd or Intigriti. For an MDR vendor whose own research unit
  publishes security advisories about other people's software, the absence of an
  inbound disclosure policy is a notable asymmetry.
contact:
  email: security@esentire.com
  attributed_to: Office of the CISO — Governance Risk and Compliance Team
  published_at: https://trust.esentire.com/
  verified: true
policy:
  published: false
  url: null
  safe_harbor: false
  sla: null
  pgp_key: null
security_txt:
  present: false
  hosts_probed:
  - host: www.esentire.com
    path: /.well-known/security.txt
    status: 404
  - host: www.esentire.com
    path: /security.txt
    status: 404
  - host: api.esentire.com
    path: /.well-known/security.txt
    status: 403
  - host: atlas.esentire.com
    path: /.well-known/security.txt
    status: 200
    note: SPA HTML shell, not a security.txt. Rejected.
bug_bounty:
  present: false
  programs_probed:
  - url: https://hackerone.com/esentire
    status: 404
  - url: https://bugcrowd.com/esentire
    status: 404
incident_hotline:
  phone: 1-866-579-2200
  purpose: >-
    eSentire's 24/7 emergency line for organizations experiencing a breach. This is
    a customer/prospect incident-response intake, NOT a vulnerability-report channel
    for eSentire's own products. Recorded to keep the two from being conflated.
  published_at: https://www.esentire.com/
related_publications:
  security_advisories: https://www.esentire.com/resources/security-advisories
  note: >-
    Outbound advisories from eSentire's Threat Response Unit (TRU) about third-party
    vulnerabilities. Not a disclosure channel for reporting issues in eSentire.
gaps:
- No vulnerability disclosure policy is published anywhere on eSentire's public surface.
- No security.txt is served, so the contact is not machine-discoverable — a researcher has to render a JavaScript trust page to find it.
- No safe-harbour language, so a good-faith researcher has no published legal assurance.
- No bug bounty or coordinated-disclosure program.
x-evidence:
  fetched: '2026-08-12'
  urls:
  - url: https://trust.esentire.com/api/trustpage/public/v1/
    status: 200
    note: Contains contactEmail security@esentire.com, contactFullName "Office of the CISO".
  - url: https://www.esentire.com/.well-known/security.txt
    status: 404
  - url: https://www.esentire.com/responsible-disclosure
    status: 404
  - url: https://www.esentire.com/vulnerability-disclosure
    status: 404
  - url: https://hackerone.com/esentire
    status: 404
  - url: https://bugcrowd.com/esentire
    status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/esentire-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.