Gainsight · Vulnerability Disclosure

Gainsight Vulnerability Disclosure

Vulnerability disclosure

Gainsight runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

Customer SuccessCustomer ExperienceProduct AnalyticsCustomer CommunitiesCustomer HealthCustomer EducationSoftware-as-a-ServiceMCPRetentionCommunity
Program: Bugcrowd

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@gainsight.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-09-17'
method: searched
source: https://www.gainsight.com/security/vulnerability-disclosure-program/
provider: Gainsight
providerId: gainsight

policy:
  - https://www.gainsight.com/security/vulnerability-disclosure-program/
contact:
  - mailto:security@gainsight.com

program:
  name: Gainsight Vulnerability Disclosure Program
  url: https://www.gainsight.com/security/vulnerability-disclosure-program/
  security_overview: https://www.gainsight.com/security/
  platform: Bugcrowd
  platform_note: >-
    The public programme pays no bounty — an accepted submission earns Bugcrowd
    kudos. Gainsight invites selected researchers to private Bugcrowd programmes
    where payouts are made "subject to issue priority and severity".
  rewards: false
  rewards_public: kudos only
  safe_harbor: partial
  safe_harbor_note: >-
    Gainsight commits to "review reports and respond in a timely manner" and sets
    researcher obligations (report promptly, avoid privacy violations and service
    disruption, limit exploitation to confirmation, keep findings confidential
    until cleared, do not modify third-party data, comply with applicable law).
    No explicit legal safe-harbour clause is stated.
  out_of_scope:
    - physical testing
    - non-security findings
    - unsolicited communications
    - findings derived from social engineering
    - malware distribution
    - DoS / DDoS

evidence:
  - source: https://www.gainsight.com/security/vulnerability-disclosure-program/
    kind: published disclosure policy page
    checked: '2026-09-17'

security_txt:
  served: false
  correction: >-
    A 2026-07-11 pass recorded a security.txt for Gainsight at
    https://support.gainsight.com/.well-known/security.txt. That file is served
    (HTTP 200, re-probed 2026-09-17) but it is NOT Gainsight's — its Contact is
    mailto:ExpertSecurity@nice.com and its Policy is
    https://expert-help.nice.com/Admin/Contact/Disclosure, the disclosure
    programme of NICE, the vendor whose documentation platform hosts
    support.gainsight.com. It was credited to Gainsight in error. Gainsight's own
    programme, recorded above, is at gainsight.com/security/ and was found by
    search rather than by discovery document.
  gainsight_owned_hosts_probed:
    - host: www.gainsight.com
      path: /.well-known/security.txt
      status: 403
      note: Cloudflare edge refuses non-browser clients; not evidence of absence.
    - host: app.gainsight.com
      path: /.well-known/security.txt
      status: 404
    - host: companyapi.gainsightcloud.com
      path: /.well-known/security.txt
      status: 404
    - host: esp.aptrinsic.com
      path: /.well-known/security.txt
      status: 404
    - host: communities.gainsight.com
      path: /.well-known/security.txt
      status: 404
  gap: >-
    Gainsight runs a real disclosure programme but publishes no RFC 9116
    security.txt on a host it controls, so a researcher or an automated scanner
    cannot discover it from the domain — only by finding the marketing page.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/gainsight-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.