Impact · Vulnerability Disclosure

Impact Vulnerability Disclosure

Vulnerability disclosure

Impact publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

AffiliatesPartnershipsPerformance MarketingCommissionTrackingCreator EconomyPartner ManagementReferralAttributionPayoutsMarketingAdvertisingMCPAgents
Program: security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://impact.responsibledisclosure.com/hc/en-us

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://impact.com/.well-known/security.txt
http_status: 200
checked: '2026-08-13'
signed: true
signature: PGP (SHA512 clearsigned)
policy:
  - https://impact.responsibledisclosure.com/hc/en-us
contact:
  - https://impact.responsibledisclosure.com/hc/en-us
encryption:
  - https://impact.com/.well-known/pgp-key.txt
acknowledgments:
  - https://impact.responsibledisclosure.com/hc/en-us/articles/360063057853-Acknowledgments
preferred_languages:
  - en
canonical: https://impact.com/.well-known/security.txt
expires: '2029-01-01T00:00:00Z'
rfc9116: true
bug_bounty:
  platform: Responsible Disclosure (impact.responsibledisclosure.com)
  paid: unknown
  scope_published: see the disclosure portal
evidence:
  - source: https://impact.com/.well-known/security.txt
    kind: security.txt (live probe)
    status: 200
    file: well-known/impact-security.txt
  - source: https://impact.com/security-and-privacy/
    kind: security and privacy page linking the responsible disclosure programme
    status: 200
notes:
  - The security.txt is PGP clearsigned and carries every optional RFC 9116 field except
    Hiring, with an Expires date well in the future.
  - Contact and Policy both resolve to the same hosted disclosure portal; there is no direct
    security email address.