Rose Rocket · Vulnerability Disclosure
Rose Rocket Vulnerability Disclosure
Vulnerability disclosure
Rose Rocket runs a real, published responsible-disclosure program with a dedicated intake address, a stated list of what to include in a report, and an explicit acknowledgement commitment. It is not a bug bounty and the company says so outright. The program's one machine-readability gap is that it is HTML only: /.well-known/security.txt returns 404 on every Rose Rocket host, so a scanner or an agent looking for the RFC 9116 discovery path finds nothing and would conclude — wrongly — that no disclosure policy exists.
Rose Rocket runs a coordinated vulnerability disclosure program on Hackerone.
TransportationLogisticsFreightTruckingTransportation Management SystemSupply ChainDispatchWebhookAuthenticationCanada
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.