RudderStack · Vulnerability Disclosure
Rudderstack Vulnerability Disclosure
Vulnerability disclosure
RudderStack publishes a named Vulnerability Disclosure Policy, linked from the site footer on every page. It defines a security vulnerability, states the scope ("any digital assets owned, operated, or maintained by RudderStack, including public facing websites"), sets out four mutual commitments (Trust, Respect, Transparency, Common Good) in both directions, and asks researchers to report through a web form on the policy page. RudderStack commits to acknowledge receipt of each report, investigate, and act.
RudderStack runs a coordinated vulnerability disclosure program on Hackerone.
Customer Data PlatformCDPData PipelineOpen-SourceEvent StreamingReverse ETLAnalyticsIdentity Resolution
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.