Netlify · Vulnerability Disclosure
Netlify Vulnerability Disclosure
Vulnerability disclosure
Netlify runs a public bug bounty programme hosted on HackerOne. It does not advertise that programme through RFC 9116 — no host Netlify serves answers /.well-known/security.txt — so the route is discoverable by a human reading the security page, but not by a scanner following the standard path.
Netlify runs a coordinated vulnerability disclosure program on Hackerone.
CDNCloudContinuous DeploymentEdge ComputingJAMstackServerlessServerless FunctionsStatic SitesWeb HostingWebsites
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.