Kudobuzz · Vulnerability Disclosure

Kudobuzz Vulnerability Disclosure

Vulnerability disclosure

Kudobuzz runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanyReviewsUser Generated ContentEcommerceSocial ProofConversion Rate OptimizationMarketingShopifyCustomer FeedbackSaaS
Program: Hackerone

Disclosure Policy

Security Contact

Contact
{"dedicated" => false, "kind" => "email", "note" => "Kudobuzz routes security disclosures to its general help address rather than a dedicated security@ mailbox. The address is Cloudflare email-obfuscated on the page and was decoded from the data-cfemail attribute.", "published_at" => "https://kudobuzz.com/security", "quote" => "\"For security concerns, disclosures, or questions about this policy, contact: Security Team, Kudobuzz, help@kudobuzz.com\"", "role" => "Security Team, Kudobuzz", "value" => "help@kudobuzz.com"}

Source

Vulnerability Disclosure

kudobuzz-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://kudobuzz.com/security
notes: >-
  The automated probe (0-working/probe-security-programs.py) returns no hit for
  Kudobuzz, because it requires bug-bounty / "responsible disclosure" /
  security@ keywords. Reading the Kudobuzz security policy page directly does
  find one real thing the probe misses: a named contact published specifically
  for disclosures. That is recorded below. It is a security CONTACT, not a
  vulnerability disclosure PROGRAM — there is no policy document, no scope
  statement, no safe-harbour language, no response-time commitment, no bug
  bounty and no security.txt. Do not read this artifact as Kudobuzz operating a
  VDP.
disclosure_program: false
policy_published: false
safe_harbour: false
bug_bounty: false
contact_published: true
contact:
  - kind: email
    value: help@kudobuzz.com
    role: Security Team, Kudobuzz
    published_at: https://kudobuzz.com/security
    dedicated: false
    note: >-
      Kudobuzz routes security disclosures to its general help address rather
      than a dedicated security@ mailbox. The address is Cloudflare
      email-obfuscated on the page and was decoded from the data-cfemail
      attribute.
    quote: >-
      "For security concerns, disclosures, or questions about this policy,
      contact: Security Team, Kudobuzz, help@kudobuzz.com"
security_policy:
  url: https://kudobuzz.com/security
  last_updated_by_provider: September 2025
  covers:
    - Security principles (confidentiality, integrity, availability)
    - Data encryption in transit (TLS/SSL) and at rest
    - Role-based access control with enforced MFA for internal admin access
    - Code review, penetration tests and vulnerability scans before deployment
    - Firewalls, intrusion detection and monitoring
    - Data retention and secure disposal
    - Sub-processor review (list available on request, not published)
    - Incident response — investigate, contain, notify without undue delay, post-incident review
    - Merchant responsibilities and a liability disclaimer
  see: security/kudobuzz-trust-center.yml
probed:
  - url: https://kudobuzz.com/.well-known/security.txt
    status: 404
  - url: https://kudobuzz.com/security.txt
    status: 404
  - url: https://kudobuzz.com/responsible-disclosure
    status: 404
  - url: https://kudobuzz.com/security/responsible-disclosure
    status: 404
  - url: https://kudobuzz.com/vulnerability-disclosure
    status: 404
  - url: https://api.kudobuzz.com/.well-known/security.txt
    status: 404
  - url: https://kudobuzz.com/security
    status: 200
bounty_platforms_checked:
  - platform: HackerOne
    result: no Kudobuzz program referenced on any Kudobuzz page
  - platform: Bugcrowd
    result: no Kudobuzz program referenced on any Kudobuzz page
  - platform: Intigriti
    result: no Kudobuzz program referenced on any Kudobuzz page
gaps:
  - No RFC 9116 /.well-known/security.txt on kudobuzz.com or api.kudobuzz.com
  - No written vulnerability disclosure policy or reporting process
  - No safe-harbour statement for good-faith researchers
  - No dedicated security@ address; disclosures share the general support inbox
  - No published triage or response-time commitment
  - No bug bounty program
evidence:
  - source: https://kudobuzz.com/security
    kind: security-policy-page
    keywords: [disclosures, security concerns, Security Team, incident response]
checked: '2026-08-13'