RudderStack · Vulnerability Disclosure

Rudderstack Vulnerability Disclosure

Vulnerability disclosure

RudderStack publishes a named Vulnerability Disclosure Policy, linked from the site footer on every page. It defines a security vulnerability, states the scope ("any digital assets owned, operated, or maintained by RudderStack, including public facing websites"), sets out four mutual commitments (Trust, Respect, Transparency, Common Good) in both directions, and asks researchers to report through a web form on the policy page. RudderStack commits to acknowledge receipt of each report, investigate, and act.

RudderStack runs a coordinated vulnerability disclosure program on Hackerone.

Customer Data PlatformCDPData PipelineOpen-SourceEvent StreamingReverse ETLAnalyticsIdentity Resolution
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.rudderstack.com/vulnerability-disclosure-policy/
url: https://www.rudderstack.com/vulnerability-disclosure-policy/
http_status: 200
description: >-
  RudderStack publishes a named Vulnerability Disclosure Policy, linked from the
  site footer on every page. It defines a security vulnerability, states the scope
  ("any digital assets owned, operated, or maintained by RudderStack, including
  public facing websites"), sets out four mutual commitments (Trust, Respect,
  Transparency, Common Good) in both directions, and asks researchers to report
  through a web form on the policy page. RudderStack commits to acknowledge
  receipt of each report, investigate, and act.
policy_published: true
scope: Any digital asset owned, operated, or maintained by RudderStack, including public-facing websites.
reporting:
  method: web form on the policy page
  email: null
  note: >-
    No dedicated security@ address is published on the policy page and there is no
    /.well-known/security.txt on any RudderStack host, so the form is the only
    named channel.
safe_harbor:
  stated: partial
  note: >-
    The policy frames researcher protection as mutual commitments rather than an
    explicit legal safe-harbour clause. It asks researchers to avoid privacy
    violations, UX degradation, production disruption and data destruction, and to
    withhold public disclosure until RudderStack has validated and addressed the
    issue.
acknowledgement_commitment: RudderStack will acknowledge receipt of each vulnerability report.
bug_bounty:
  program: false
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti program was found.
security_txt:
  published: false
  probed:
    - {url: 'https://www.rudderstack.com/.well-known/security.txt', status: 404}
    - {url: 'https://api.rudderstack.com/.well-known/security.txt', status: 404}
evidence:
  - source: https://www.rudderstack.com/vulnerability-disclosure-policy/
    http_status: 200
    kind: disclosure policy page
    keywords:
      - vulnerability disclosure policy
      - security researchers
      - security vulnerability
      - responsible manner
      - vulnerability reporting
  - source: https://www.rudderstack.com/security/
    http_status: 200
    kind: security overview page linking the disclosure policy