RealSelf · Vulnerability Disclosure

Realself Vulnerability Disclosure

Vulnerability disclosure

RealSelf runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

CompanyHealthcareAestheticsMarketplaceReviewsLead GenerationConsumer HealthWebhookJSON-Schema
Program: Bugcrowd

Disclosure Policy

Policy
Policy

Security Contact

Contact
security@realself.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-26'
method: searched
probe: true
source: https://www.realself.com/.well-known/security.txt
summary: >-
  RealSelf serves an RFC 9116 security.txt at both the apex and www hosts. It names a
  security contact address and two Policy URLs — a security page on the marketing host
  and a Bugcrowd program. The Bugcrowd URL the file advertises did not resolve to a
  public program when probed on 2026-08-26, so the bounty program is either private
  (invitation-only, which Bugcrowd does not list publicly) or the pointer is stale.
  The disclosure contact itself is real and served.
contact:
- security@realself.com
policy:
- url: https://www.realself.com/security/
  status: 403
  note: >-
    Fastly edge answers our crawler with a reCAPTCHA "Access has been denied" interstitial
    for every path on the app host. Not treated as dead — RealSelf's own security.txt
    asserts this page, and /news on the same host returns 200.
- url: https://bugcrowd.com/realself
  status: 404
  note: >-
    Advertised in security.txt as a Policy URL. Bugcrowd returns "Resource not found 404"
    for both /realself and /engagements/realself, so no public program page exists.
preferred_languages:
- en
bug_bounty:
  platform: bugcrowd
  advertised: true
  public_program_found: false
  evidence: https://bugcrowd.com/realself returned 404 on 2026-08-26
evidence:
- url: https://www.realself.com/.well-known/security.txt
  status: 200
  content_type: text/plain; charset=UTF-8
  file: well-known/realself-security.txt
- url: https://realself.com/.well-known/security.txt
  status: 200
- url: https://bugcrowd.com/realself
  status: 404
- url: https://bugcrowd.com/engagements/realself
  status: 404

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/realself-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.