Klaviyo · Vulnerability Disclosure

Klaviyo Vulnerability Disclosure

Vulnerability disclosure

Klaviyo runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

MarketingEmailSMSCustomer DataE-CommerceAutomation
Program: Bugcrowd

Disclosure Policy

Policy
Policy

Security Contact

Contact
security@klaviyo.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.klaviyo.com/security/bug-reporting

program:
  published: true
  type: managed bug bounty + coordinated vulnerability disclosure
  platform: Bugcrowd
  platform_url: https://bugcrowd.com/engagements/klaviyo-og
  platform_engagement_name: Klaviyo Managed Bug Bounty
  access: invite-only
  access_detail: >-
    The Bugcrowd bounty program is invite-only. Researchers who are not invited submit
    suspected vulnerabilities through the public web form at
    https://www.klaviyo.com/security/bug-reporting, so the disclosure channel itself is
    open even though the paid program is not.
  public_disclosure_permitted: true
  public_disclosure_note: Governed by Bugcrowd's standard disclosure guidelines.

policy:
  - https://www.klaviyo.com/security/bug-reporting
  - https://bugcrowd.com/engagements/klaviyo-og

contact:
  - security@klaviyo.com
contact_other:
  - {address: abuse@klaviyo.com, purpose: abuse and spam reports (not security vulnerabilities)}

security_txt:
  served: false
  detail: >-
    Klaviyo does NOT publish an RFC 9116 security.txt. /.well-known/security.txt returns
    404 on www.klaviyo.com, klaviyo.com and a.klaviyo.com; developers.klaviyo.com returns
    200 but with the ReadMe.io HTML SPA shell, which is not a document. This is the one
    gap in an otherwise well-published program — a machine reading only
    /.well-known/security.txt would conclude Klaviyo has no disclosure channel.
  probes:
    - {url: 'https://www.klaviyo.com/.well-known/security.txt', status: 404}
    - {url: 'https://klaviyo.com/.well-known/security.txt', status: 404}
    - {url: 'https://a.klaviyo.com/.well-known/security.txt', status: 404}
    - {url: 'https://developers.klaviyo.com/.well-known/security.txt', status: 200, content_type: text/html, verdict: SPA shell — not a document}

additional_assurance:
  - Annual third-party penetration testing
  - Bug bounty program with external security researchers

evidence:
  - {source: 'https://www.klaviyo.com/security/bug-reporting', http_status: 200, keywords: [bug bounty, BugCrowd, vulnerability disclosure, invite only, security@klaviyo.com]}
  - {source: 'https://www.klaviyo.com/trust', http_status: 200, keywords: [bug bounty, security@klaviyo.com]}
  - {source: 'https://bugcrowd.com/engagements/klaviyo-og', http_status: 200, keywords: [Bug Bounty, Bugcrowd VRT, public disclosure is permitted]}
  - {source: 'https://www.klaviyo.com/security', http_status: 200, keywords: [security@klaviyo, vulnerability]}

x-evidence:
  fetched: '2026-08-13'