Porsche · Vulnerability Disclosure
Porsche Vulnerability Disclosure
Vulnerability disclosure
Porsche runs two distinct vulnerability-disclosure channels: a corporate one advertised through RFC 9116 security.txt on porsche.com, and a repository-scoped one for the Porsche Design System that uses GitHub private vulnerability reporting and publishes response-time targets and a safe-harbor clause. No public bug bounty program (HackerOne, Bugcrowd, Intigriti) was found.
Porsche runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
AutomobilesCarsVehiclesAutomotiveConnected CarIdentityOpenID ConnectDesign SystemOpen-SourceGermany
Program: Hackerone
security.txt present
Disclosure Policy
Policy
Policy
Security Contact
Contact
mailto:security@porsche.de
Contact
mailto:vulnerability@porsche.de
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.