LevelBlue · Vulnerability Disclosure

Levelblue Vulnerability Disclosure

Vulnerability disclosure

LevelBlue runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyEnterpriseCybersecuritySecurityThreat IntelligenceManaged SecuritySIEMThreat DetectionIncident ResponseCompliance
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy
Policy

Security Contact

Contact
mailto:levelblue@submit.bugcrowd.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-19'
method: searched
probe: true
source: well-known/levelblue-security.txt

policy:
- https://docs.levelblue.com/documentation/how-to-submit-a-security-issue
- https://hackerone.com/att
- https://www.levelblue.com/legal/privacy-policy

contact:
- mailto:levelblue@submit.bugcrowd.com

programs:
- name: LevelBlue vulnerability submission (Bugcrowd)
  platform: Bugcrowd
  intake: mailto:levelblue@submit.bugcrowd.com
  evidence: Contact field of https://www.levelblue.com/.well-known/security.txt
- name: AT&T Bug Bounty Program
  platform: HackerOne
  url: https://hackerone.com/att
  evidence: >-
    The LevelBlue documentation page "How to Submit a Security Issue to LevelBlue"
    directs researchers to disclose through the AT&T Bug Bounty Program managed by
    HackerOne, where program guidelines, exclusions, terms, reporting process and
    awarding process are published.
  note: >-
    Inherited from LevelBlue's origin as AT&T Cybersecurity; the docs page still refers to
    AT&T as the operating entity.

security_txt:
  url: https://www.levelblue.com/.well-known/security.txt
  file: well-known/levelblue-security.txt
  standard: RFC 9116
  fields:
    contact: mailto:levelblue@submit.bugcrowd.com
    expires: '2027-02-01T00:00:00.000Z'
    preferred_languages: en
    canonical: https://www.levelblue.com/.well-known/security.txt
    policy: https://www.levelblue.com/legal/privacy-policy
    hiring: https://jobs.dayforcehcm.com/en-US/twh/CANDIDATEPORTAL?searchText=security
  observations:
  - >-
      The Policy field points at the general website privacy policy rather than a
      vulnerability disclosure policy — the actual disclosure policy lives on the
      HackerOne program page and the docs "How to Submit a Security Issue" page.
  - No Encryption, Acknowledgments or CSAF field is published.

submission_guidance:
  source: https://docs.levelblue.com/documentation/how-to-submit-a-security-issue
  requested_detail:
  - Steps and any additional information needed to reproduce the issue.
  - For XSS, an exploit that at minimum pops an alert; showing the auth cookie is preferred.
  - For CSRF, a proper case where a third party causes the logged-in victim to perform an action.
  - For SQL injection, an exploit extracting database data rather than only producing an error.
  - HTTP request/response captures or packet captures.

evidence:
- source: well-known/levelblue-security.txt
  kind: security.txt
- source: https://docs.levelblue.com/documentation/how-to-submit-a-security-issue
  kind: disclosure-page
  keywords: [bug bounty, hackerone, responsible disclosure, security vulnerability]

trust_center:
  found: false
  checked:
  - https://trust.levelblue.com (no DNS resolution)
  - https://www.levelblue.com/trust (404)
  - https://www.levelblue.com/security (404)
  - https://www.levelblue.com/company/compliance (404)
  note: >-
    No public trust center or certifications page was found, so no TrustCenter or
    Compliance pointer is emitted. LevelBlue documents compliance as a product capability
    (PCI DSS reporting in USM Anywhere, FedRAMP authorization for LevelBlue TDR for Gov) —
    see conformance/levelblue-conformance.yml — but publishes no corporate certification
    inventory.