RainFocus · Vulnerability Disclosure
Rainfocus Vulnerability Disclosure
Vulnerability disclosure
RainFocus publishes a vulnerability disclosure policy for reporting security issues.
CompanyEventEvent ManagementEvent MarketingRegistrationConferencesWebinarsMarketing TechnologyAttendee DataMCPAgentsEnterprise SoftwareSoftware-as-a-Service
Program:
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-26'
method: searched
probe: true
source: https://www.rainfocus.com/privacy-security/vulnerability-disclosure/
program:
published: true
name: RainFocus Vulnerability Disclosure Program
type: coordinated-disclosure
bug_bounty: false
bounty_note: >-
No monetary reward. The policy offers public recognition only for accepted submissions.
contact_email: security@rainfocus.com
contact_instructions: >-
Email security@rainfocus.com with the subject line "Finding for Vulnerability Disclosure
Program".
pgp_key: null
safe_harbor: partial
safe_harbor_note: >-
No traditional safe-harbor grant. The policy expressly states it is not "any sort of permission
or license to engage in practices which would violate federal or state law" and cites the
Computer Fraud and Abuse Act.
scope_in:
- https://app-was.rainfocus.com
- https://reg-was.rainfocus.com
scope_note: >-
Only the two named research sites are approved for testing. Vulnerabilities found on any other
RainFocus site must be reported immediately without exploiting or modifying the site. Neither
research host resolves publicly from this network (DNS did not answer), so both are presumed
allowlist-gated.
response_sla: null
response_sla_note: >-
No committed response time. The policy says review time varies with the complexity and
completeness of the submission and the volume received.
disclosure_window_days: 90
disclosure_window_note: >-
Researchers are asked to allow RainFocus at least 90 days to diagnose and ship fully tested
updates before public disclosure.
related_terms: https://www.rainfocus.com/privacy-security/api-terms-and-conditions/
related_terms_note: >-
The API and MCP Tools terms forbid penetration testing or vulnerability scanning of the
Developer Tools without RainFocus's prior written approval, so the API and MCP surfaces are NOT
covered by the disclosure program's testing permission.
security_txt:
served: false
probed:
- url: https://www.rainfocus.com/.well-known/security.txt
status: 403
- url: https://api.rainfocus.com/.well-known/security.txt
status: 404
- url: https://events.rainfocus.com/.well-known/security.txt
status: 404
note: >-
RainFocus runs a real disclosure program but publishes no RFC 9116 security.txt on any host, so
a machine cannot discover the reporting address without reading the marketing site.
evidence:
- source: https://www.rainfocus.com/privacy-security/vulnerability-disclosure/
status: 200
kind: disclosure policy page
- source: https://www.rainfocus.com/vulnerability-disclosure/
status: 200
kind: alternate path serving the same policy
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rainfocus-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.