Rose Rocket · Vulnerability Disclosure

Rose Rocket Vulnerability Disclosure

Vulnerability disclosure

Rose Rocket runs a real, published responsible-disclosure program with a dedicated intake address, a stated list of what to include in a report, and an explicit acknowledgement commitment. It is not a bug bounty and the company says so outright. The program's one machine-readability gap is that it is HTML only: /.well-known/security.txt returns 404 on every Rose Rocket host, so a scanner or an agent looking for the RFC 9116 discovery path finds nothing and would conclude — wrongly — that no disclosure policy exists.

Rose Rocket runs a coordinated vulnerability disclosure program on Hackerone.

TransportationLogisticsFreightTruckingTransportation Management SystemSupply ChainDispatchWebhookAuthenticationCanada
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-26'
method: searched
source: https://www.roserocket.com/responsible-disclosure
source_status: 200
probed: '2026-08-26'
description: >-
  Rose Rocket runs a real, published responsible-disclosure program with a dedicated
  intake address, a stated list of what to include in a report, and an explicit
  acknowledgement commitment. It is not a bug bounty and the company says so
  outright. The program's one machine-readability gap is that it is HTML only:
  /.well-known/security.txt returns 404 on every Rose Rocket host, so a scanner or
  an agent looking for the RFC 9116 discovery path finds nothing and would conclude —
  wrongly — that no disclosure policy exists.
program:
  exists: true
  type: responsible disclosure
  policy_url: https://www.roserocket.com/responsible-disclosure
  contact: responsibledisclosure@roserocket.com
  contact_type: email
  statement: >-
    "At Rose Rocket, we deeply value the security of your information. Therefore, we
    encourage anyone who believes they have discovered potential security
    vulnerabilities to report them to us and help us improve and maintain our security
    measures."
  requested_report_contents:
    - Detailed description of your discovery
    - The applicable URL at which you discovered the vulnerability
    - Any relevant screen captures / screen recordings
    - Steps taken to identify the vulnerability
    - Tools used
    - Any other relevant information or details
  acknowledgement: >-
    "Once we receive your report, we will acknowledge receipt with an automated reply.
    Our team will make our best effort to investigate and address any identified
    vulnerabilities in a timely manner."
  response_sla: none stated (best effort)
  safe_harbor: not stated
  scope_definition: not published
  hall_of_fame: none
bug_bounty:
  exists: false
  statement: >-
    "Please note that Rose Rocket does not currently operate a 'Bug Bounty' program. We
    make no offer of reward or compensation in exchange for submitting potential
    vulnerabilities."
  platforms_checked: [HackerOne, Bugcrowd, Intigriti]
  platforms_result: no program found
security_txt:
  published: false
  rfc9116: false
  probes:
    - {url: 'https://www.roserocket.com/.well-known/security.txt', status: 404}
    - {url: 'https://roserocket.com/.well-known/security.txt', status: 404}
    - {url: 'https://network.roserocket.com/.well-known/security.txt', status: 404}
    - {url: 'https://a.roserocket.com/.well-known/security.txt', status: 404}
    - {url: 'https://platform.roserocket.com/.well-known/security.txt', status: 404}
    - {url: 'https://roserocket.readme.io/.well-known/security.txt', status: 404}
  recommendation: >-
    A one-line security.txt at https://www.roserocket.com/.well-known/security.txt with
    Contact: mailto:responsibledisclosure@roserocket.com and
    Policy: https://www.roserocket.com/responsible-disclosure would make an existing,
    working program discoverable by machine. The content already exists; only the
    discovery path is missing.
related:
  trust_center:
    exists: false
    note: >-
      No trust centre portal. trust.roserocket.com resolves (HTTP 200) but returns the
      Rose Rocket application shell, not a trust page — a wildcard host, not a program.
  certifications:
    - {name: SOC 2, claimed: true, evidence: 'https://www.roserocket.com/solutions/security', detail: See conformance/rose-rocket-conformance.yml.}

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rose-rocket-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.