Rye · Vulnerability Disclosure

Rye Vulnerability Disclosure

Vulnerability disclosure

Rye publishes a security contact and vulnerability-reporting path via /.well-known/security.txt (RFC 9116) and its security documentation page. Reports go to security@rye.com; a PGP key is offered for encrypted reports. No public bug-bounty program (HackerOne/Bugcrowd/Intigriti) was found.

Rye runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyCommerceE-CommerceCheckoutPaymentsAgentic CommerceAI AgentsUniversal CheckoutShopping
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security@rye.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-21'
method: searched
probe: true
description: >-
  Rye publishes a security contact and vulnerability-reporting path via
  /.well-known/security.txt (RFC 9116) and its security documentation page.
  Reports go to security@rye.com; a PGP key is offered for encrypted reports.
  No public bug-bounty program (HackerOne/Bugcrowd/Intigriti) was found.
policy:
  - https://rye.com/docs/api-v2/security
contact:
  - security@rye.com
encryption: https://rye.com/pgp-key.txt
evidence:
  - source: well-known/rye-security.txt
    kind: security.txt
  - source: https://rye.com/docs/api-v2/security
    kind: security-docs
    note: "To report a security vulnerability, please email us at security@rye.com"