Proofpoint · Vulnerability Disclosure

Proofpoint Vulnerability Disclosure

Vulnerability disclosure

Proofpoint runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

SecurityCybersecurityEmail SecurityThreat IntelligenceData Loss PreventionSecurity Awareness TrainingInsider ThreatSIEMComplianceEmail
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
mailto:security@proofpoint.com

Source

Vulnerability Disclosure

proofpoint-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-13'
method: searched
source: https://www.proofpoint.com/us/security/vulnerability-disclosure-policy
name: Proofpoint Vulnerability Disclosure Policy
policy:
- https://www.proofpoint.com/us/security/vulnerability-disclosure-policy
contact:
- mailto:security@proofpoint.com
program:
  type: vulnerability-disclosure-policy
  bug_bounty: unconfirmed
  platform: HackerOne
  platform_url: https://hackerone.com/proofpoint
  platform_note: 'A HackerOne page exists at hackerone.com/proofpoint and returns HTTP
    200, but the page body is a JavaScript shell ("It looks like your JavaScript is
    disabled") so the program scope, bounty table and status could not be read without
    a browser. Recorded as present-but-unread rather than as a confirmed paid bounty.'
  hall_of_fame: true
  cve_issuance: true
scope:
  included: Proofpoint Products
  excluded: Third party products
  note: 'Policy text: "This Policy applies to Proofpoint Products. Third party products
    are excluded from the scope of this Policy." Researchers unsure whether a system
    is in scope are told to contact security@proofpoint.com before starting.'
researcher_obligations:
- Cease further testing and promptly submit a report to security@proofpoint.com
- No social engineering, physical security testing or other non-technical security testing
researcher_benefits:
- Recognition on Proofpoint's Hall of Fame (with permission)
- CVE identifiers for legitimate vulnerabilities in Proofpoint Products, publicly disclosed
  via Proofpoint Security Advisories
evidence:
- url: https://www.proofpoint.com/us/security/vulnerability-disclosure-policy
  http_status: 200
  kind: published vulnerability disclosure policy
- url: https://hackerone.com/proofpoint
  http_status: 200
  kind: bug bounty platform page (JS-rendered, body unread)
- url: https://www.proofpoint.com/us/security
  http_status: 200
  kind: Proofpoint Security hub
x-correction:
  note: 'CORRECTED 2026-09-13. probe-security-programs.py first wrote this file crediting
    Proofpoint with a security.txt at https://help.proofpoint.com/.well-known/security.txt.
    That document is real and returns HTTP 200, but it belongs to NICE, not Proofpoint:
    it declares Contact mailto:ExpertSecurity@nice.com and Policy
    https://expert-help.nice.com/Admin/Contact/Disclosure. help.proofpoint.com is a
    MindTouch / NICE CXone Expert tenant and the platform serves its own security.txt
    on every customer subdomain. Proofpoint itself serves no security.txt on any host
    probed (see well-known/proofpoint-well-known.yml); its real disclosure policy is
    an HTML page on www.proofpoint.com.'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/proofpoint-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.