Monaco · Vulnerability Disclosure

Monaco Vulnerability Disclosure

Vulnerability disclosure

Monaco runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyCRMSalesRevenue OperationsArtificial IntelligenceContactsAccountsOpportunitiesPipelineGo To MarketMCPCampaignsAudiencesSales EngagementAgents
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@monaco.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.monaco.com/vulnerability-disclosure
docs:
- https://www.monaco.com/security
- https://www.monaco.com/vulnerability-disclosure
- well-known/monaco-security.txt
policy:
- https://www.monaco.com/security
contact:
- mailto:security@monaco.com
submission:
  platform: HackerOne
  program_url: https://hackerone.com/9fd2f603-ce51-4018-983f-90ba2be192d1
  embedded_form: https://hackerone.com/9fd2f603-ce51-4018-983f-90ba2be192d1/embedded_submissions/new?locale=en
  note: >-
    Reports are submitted through Monaco's HackerOne disclosure program (embedded
    submission form) and triaged by Monaco's security team. Email to
    security@monaco.com is also accepted.
encryption:
  pgp_fingerprint: 54FC 7122 1433 4900 FE9F 2921 BAB2 7553 F3F9 A8B7
  key_url: https://keys.openpgp.org/vks/v1/by-fingerprint/54FC712214334900FE9F2921BAB27553F3F9A8B7
bounty:
  monetary_rewards: false
  note: >-
    Monaco states it does not currently offer monetary rewards; public
    acknowledgment is offered with the researcher's consent.
scope:
  in_scope:
  - www.monaco.com — marketing and landing site
  - app.monaco.com — Monaco web application
  - api.monaco.com — Monaco public API
  out_of_scope:
  - Third-party integrated services
  - Social engineering of employees, contractors, or customers
  - Physical attacks against offices or infrastructure
  - Denial-of-service, volumetric or load testing
  - Automated scanner findings without demonstrated impact
  - Unsupported browsers / end-of-life software
  - Missing security headers without a concrete exploit
  - Clickjacking on pages with no sensitive actions
  - Self-XSS and issues requiring physical device access
safe_harbor:
  offered: true
  conditions:
  - Good-faith effort to avoid privacy violations, data destruction, and service disruption
  - Only interact with accounts you own or have explicit permission to access
  - Do not exploit beyond what is necessary to demonstrate the issue
  - Give Monaco reasonable time to remediate before public disclosure
  - Comply with all applicable laws
commitments:
  acknowledgment: within 5 business days
  triage: assessment and expected remediation timeline as quickly as possible after acknowledgment
  updates: researcher kept informed of remediation progress
  credit: public credit on request once the issue is resolved
coordinated_disclosure:
  embargo_days: 90
  note: Critical issues are handled on a coordinated timeline agreed with the reporter.
policy_last_updated: '2026-04-20'
evidence:
- source: well-known/monaco-security.txt
  kind: security.txt
  fields: [Contact, Policy, Encryption, Expires, Preferred-Languages, Canonical]
- source: https://www.monaco.com/security
  kind: security policy page
  http_status: 200
- source: https://www.monaco.com/vulnerability-disclosure
  kind: disclosure submission page
  http_status: 200