Salesloft · Vulnerability Disclosure

Salesloft Vulnerability Disclosure

Vulnerability disclosure

Salesloft publishes a substantive public security-program page and states on it that it runs an ongoing bug-bounty program with independent penetration testers, plus annual third-party security assessments. What it does NOT publish is a way in: there is no /.well-known/security.txt on any Salesloft host, no responsible-disclosure or vulnerability-disclosure-policy page, no public HackerOne or Bugcrowd program, and no security@ contact address anywhere on the public site. A researcher who finds a bug in Salesloft today has no published intake channel.

Salesloft runs a coordinated vulnerability disclosure program on Hackerone.

SalesSales EngagementCadencesCRMEmailRevenue IntelligenceConversation IntelligenceSales AutomationWebhookMCPAgentsDialerPipelineForecasting
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.salesloft.com/security
description: >-
  Salesloft publishes a substantive public security-program page and states on it that it runs
  an ongoing bug-bounty program with independent penetration testers, plus annual third-party
  security assessments. What it does NOT publish is a way in: there is no /.well-known/security.txt
  on any Salesloft host, no responsible-disclosure or vulnerability-disclosure-policy page, no
  public HackerOne or Bugcrowd program, and no security@ contact address anywhere on the public
  site. A researcher who finds a bug in Salesloft today has no published intake channel.
policy:
  - https://www.salesloft.com/security
contact: []
security_txt: false
bug_bounty:
  claimed: true
  public_program: false
  platform: null
  quote: >-
    "our bug-bounty program entails penetration testing by independent security professionals on
    an ongoing basis; and security assessments are performed on a project basis at least annually
    by a reputable independent security-consulting firm. Reported vulnerabilities are assessed,
    prioritized based on risk, and tracked through dispensation."
security_program:
  data_centers: 'AWS and GCP, US and EU (Drift on AWS, US)'
  encryption_in_transit: 'HTTPS / TLS 1.2+'
  encryption_at_rest: 'AES-256-GCM, plus IaaS disk-level encryption; keys managed and auto-rotated by the provider KMS'
  team: 'Information Security team under the CIO — Security Engineering, Security Operations, and GRC'
  monitoring: 'WAF, SCA/dependency scanning, log aggregation, EDR/XDR, PAM, SIEM with 24x365 partner monitoring and on-call escalation'
  access_control: 'Least access required; production access via PAM with role-based permissions, approval groups, time-limited sessions and MFA'
  sdlc: 'Mandatory secure-development training; CI/CD with automated code scans, peer review and QA approval gates'
  certifications_page: https://trust.salesloft.com/
evidence:
  - {source: 'https://www.salesloft.com/security', kind: security-program-page, status: 200, keywords: [bug-bounty, penetration testing, reported vulnerabilities, security assessments]}
  - {source: 'https://trust.salesloft.com/', kind: trust-center, status: 200}
gaps:
  - {check: '/.well-known/security.txt on www.salesloft.com', status: 404}
  - {check: '/.well-known/security.txt on api.salesloft.com', status: 401}
  - {check: '/.well-known/security.txt on developers.salesloft.com', status: 404}
  - {check: 'https://hackerone.com/salesloft', status: 404}
  - {check: 'https://bugcrowd.com/salesloft', status: 404}
  - {check: 'https://www.salesloft.com/legal/responsible-disclosure', status: 404}
  - {check: 'https://www.salesloft.com/responsible-disclosure', status: 404}
  - {check: 'https://www.salesloft.com/legal/vulnerability-disclosure-policy', status: 404}
recommendation: >-
  Publishing an RFC 9116 /.well-known/security.txt with a Contact and a Policy URL would close
  this in an afternoon and is the single cheapest security-posture improvement available to
  Salesloft — the program already exists; only the front door is missing.
x-evidence:
  fetched: '2026-08-13'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/salesloft-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.