Rybbit · Vulnerability Disclosure
Rybbit Vulnerability Disclosure
Vulnerability disclosure
Rybbit runs an email-based responsible-disclosure program with no monetary rewards. It is documented in three consistent places: a served RFC 9116 security.txt, a SECURITY.md in the public repository with a supported-version table and a 72-hour acknowledgement commitment, and a "Vulnerability Disclosure" section on the security page. There is no bug bounty and no HackerOne / Bugcrowd / Intigriti presence.
Rybbit runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
AnalyticsWeb AnalyticsProduct AnalyticsPrivacyOpen-SourceCookieless
Program: Hackerone
security.txt present
Disclosure Policy
Security Contact
Contact
mailto:hello@rybbit.com
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.