Rallyware · Vulnerability Disclosure

Rallyware Vulnerability Disclosure

Vulnerability disclosure

Rallyware runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanySales EnablementWorkforce EnablementLearning and DevelopmentPerformance ManagementGamificationDirect SellingEnterprise Software
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
ops@rallyware.com

Source

Vulnerability Disclosure

rallyware-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.rallyware.com/security-2
policy:
- https://www.rallyware.com/security-2
contact:
- ops@rallyware.com
program:
  type: bug bounty
  name: Bug Bounty Program
  url: https://www.rallyware.com/security-2
  rewards: true
  reward_model: >-
    "The researcher receives a reward according to the vulnerability category."
    No reward table, minimum, or maximum is published.
  platform: none
  platform_note: >-
    Self-run. No HackerOne, Bugcrowd, Intigriti or other third-party platform is
    used; reports go directly to the contact address by email.
  scope: >-
    "Security researchers can test our public services and products." No explicit
    in-scope/out-of-scope asset list is published.
  rules:
  - DoS/DDoS attacks are prohibited.
  - Social engineering is prohibited.
  - Physical intrusion is prohibited.
  - >-
    Responsible disclosure required — "the researcher is not allowed to publish
    details until the vulnerability is fixed." No coordinated-disclosure deadline is
    stated.
  stated_purpose:
  - Provide an additional layer of protection for products and services.
  - Create a transparent channel of communication with independent security researchers.
  - Receive information about potential risks in time to eliminate them.
  triage_commitment: >-
    "We promptly analyze the message, confirm the finding and determine the level of
    criticality." No SLA or response-time commitment is given.

related_practices:
- Annual independent penetration testing.
- Information Security Management System (ISMS), updated annually and reviewed
  through internal and external audits.
- Business continuity and disaster recovery plans, regularly tested.

security_txt:
  served: false
  path: /.well-known/security.txt
  status: 404
  probed: '2026-08-14'
  gap: >-
    Rallyware runs a real bug bounty with a published contact address but serves no
    RFC 9116 security.txt. A four-line file naming Contact: mailto:ops@rallyware.com
    and Policy: https://www.rallyware.com/security-2 would make the program
    machine-discoverable at zero cost. This is the single cheapest security-posture
    improvement available to this provider.

evidence:
- source: https://www.rallyware.com/security-2
  kind: disclosure page
  http_status: 200
  keywords:
  - bug bounty
  - vulnerability
  - responsible disclosure
  - security research
  - penetration testing
- source: https://www.rallyware.com/.well-known/security.txt
  kind: security.txt probe
  http_status: 404
note: >-
  The reporting address is published on the page behind Cloudflare email obfuscation
  (data-cfemail); it decodes to ops@rallyware.com. Recorded because it is the address
  Rallyware itself directs researchers to, in the sentence "If a vulnerability is
  discovered, they report it directly to ...".

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rallyware-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.