RudderStack · Vulnerability Disclosure

Rudderstack Vulnerability Disclosure

Vulnerability disclosure

RudderStack publishes a named Vulnerability Disclosure Policy, linked from the site footer on every page. It defines a security vulnerability, states the scope ("any digital assets owned, operated, or maintained by RudderStack, including public facing websites"), sets out four mutual commitments (Trust, Respect, Transparency, Common Good) in both directions, and asks researchers to report through a web form on the policy page. RudderStack commits to acknowledge receipt of each report, investigate, and act.

RudderStack runs a coordinated vulnerability disclosure program on Hackerone.

Customer Data PlatformCDPData PipelineOpen-SourceEvent StreamingReverse ETLAnalyticsIdentity Resolution
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.rudderstack.com/vulnerability-disclosure-policy/
url: https://www.rudderstack.com/vulnerability-disclosure-policy/
http_status: 200
description: >-
  RudderStack publishes a named Vulnerability Disclosure Policy, linked from the
  site footer on every page. It defines a security vulnerability, states the scope
  ("any digital assets owned, operated, or maintained by RudderStack, including
  public facing websites"), sets out four mutual commitments (Trust, Respect,
  Transparency, Common Good) in both directions, and asks researchers to report
  through a web form on the policy page. RudderStack commits to acknowledge
  receipt of each report, investigate, and act.
policy_published: true
scope: Any digital asset owned, operated, or maintained by RudderStack, including public-facing websites.
reporting:
  method: web form on the policy page
  email: null
  note: >-
    No dedicated security@ address is published on the policy page and there is no
    /.well-known/security.txt on any RudderStack host, so the form is the only
    named channel.
safe_harbor:
  stated: partial
  note: >-
    The policy frames researcher protection as mutual commitments rather than an
    explicit legal safe-harbour clause. It asks researchers to avoid privacy
    violations, UX degradation, production disruption and data destruction, and to
    withhold public disclosure until RudderStack has validated and addressed the
    issue.
acknowledgement_commitment: RudderStack will acknowledge receipt of each vulnerability report.
bug_bounty:
  program: false
  platform: null
  note: No HackerOne, Bugcrowd or Intigriti program was found.
security_txt:
  published: false
  probed:
    - {url: 'https://www.rudderstack.com/.well-known/security.txt', status: 404}
    - {url: 'https://api.rudderstack.com/.well-known/security.txt', status: 404}
evidence:
  - source: https://www.rudderstack.com/vulnerability-disclosure-policy/
    http_status: 200
    kind: disclosure policy page
    keywords:
      - vulnerability disclosure policy
      - security researchers
      - security vulnerability
      - responsible manner
      - vulnerability reporting
  - source: https://www.rudderstack.com/security/
    http_status: 200
    kind: security overview page linking the disclosure policy

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/rudderstack-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.