RainFocus · Vulnerability Disclosure

Rainfocus Vulnerability Disclosure

Vulnerability disclosure

RainFocus publishes a vulnerability disclosure policy for reporting security issues.

CompanyEventEvent ManagementEvent MarketingRegistrationConferencesWebinarsMarketing TechnologyAttendee DataMCPAgentsEnterprise SoftwareSoftware-as-a-Service
Program:

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

rainfocus-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-26'
method: searched
probe: true
source: https://www.rainfocus.com/privacy-security/vulnerability-disclosure/
program:
  published: true
  name: RainFocus Vulnerability Disclosure Program
  type: coordinated-disclosure
  bug_bounty: false
  bounty_note: >-
    No monetary reward. The policy offers public recognition only for accepted submissions.
  contact_email: security@rainfocus.com
  contact_instructions: >-
    Email security@rainfocus.com with the subject line "Finding for Vulnerability Disclosure
    Program".
  pgp_key: null
  safe_harbor: partial
  safe_harbor_note: >-
    No traditional safe-harbor grant. The policy expressly states it is not "any sort of permission
    or license to engage in practices which would violate federal or state law" and cites the
    Computer Fraud and Abuse Act.
  scope_in:
  - https://app-was.rainfocus.com
  - https://reg-was.rainfocus.com
  scope_note: >-
    Only the two named research sites are approved for testing. Vulnerabilities found on any other
    RainFocus site must be reported immediately without exploiting or modifying the site. Neither
    research host resolves publicly from this network (DNS did not answer), so both are presumed
    allowlist-gated.
  response_sla: null
  response_sla_note: >-
    No committed response time. The policy says review time varies with the complexity and
    completeness of the submission and the volume received.
  disclosure_window_days: 90
  disclosure_window_note: >-
    Researchers are asked to allow RainFocus at least 90 days to diagnose and ship fully tested
    updates before public disclosure.
  related_terms: https://www.rainfocus.com/privacy-security/api-terms-and-conditions/
  related_terms_note: >-
    The API and MCP Tools terms forbid penetration testing or vulnerability scanning of the
    Developer Tools without RainFocus's prior written approval, so the API and MCP surfaces are NOT
    covered by the disclosure program's testing permission.
security_txt:
  served: false
  probed:
  - url: https://www.rainfocus.com/.well-known/security.txt
    status: 403
  - url: https://api.rainfocus.com/.well-known/security.txt
    status: 404
  - url: https://events.rainfocus.com/.well-known/security.txt
    status: 404
  note: >-
    RainFocus runs a real disclosure program but publishes no RFC 9116 security.txt on any host, so
    a machine cannot discover the reporting address without reading the marketing site.
evidence:
- source: https://www.rainfocus.com/privacy-security/vulnerability-disclosure/
  status: 200
  kind: disclosure policy page
- source: https://www.rainfocus.com/vulnerability-disclosure/
  status: 200
  kind: alternate path serving the same policy

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rainfocus-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.