Revv · Vulnerability Disclosure

Revv Vulnerability Disclosure

Vulnerability disclosure

Revv runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyDocument AutomationElectronic SignatureContract ManagementSales EnablementWorkflow AutomationSaaS
Program: Hackerone security.txt present

Disclosure Policy

Security Contact

Contact
security@revvsales.com

Source

Vulnerability Disclosure

revv-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.revv.so/trust/security.html
policy: []
contact:
- security@revvsales.com
bug_bounty: null
security_txt: false
note: >-
  Revv publishes a security contact but no disclosure programme. The only channel found
  is a mailto:security@revvsales.com link on the Trust Center page (note the address is
  on the legacy revvsales.com domain, the pre-rename company name). There is no
  responsible-disclosure or vulnerability-disclosure policy page, no safe-harbour
  statement, no bug bounty (HackerOne / Bugcrowd / Intigriti all absent), and no
  /.well-known/security.txt on any Revv host — www.revv.so returns 404 for it and the
  product subdomains answer 200 with a LegalZoom SPA shell, which is not a document. No
  `Security` pointer is emitted: a contact address alone is not a published disclosure
  policy.
evidence:
- source: https://www.revv.so/trust/security.html
  kind: security-contact
  detail: mailto:security@revvsales.com in the Trust Center page markup
  status: 200
- source: https://www.revv.so/.well-known/security.txt
  kind: security.txt
  detail: not served
  status: 404
x-evidence:
- url: https://www.revv.so/trust/security.html
  status: 200
  fetched: '2026-08-14'
- url: https://www.revv.so/.well-known/security.txt
  status: 404
  fetched: '2026-08-14'