Salesforce Service Cloud APIs · Vulnerability Disclosure
Service Cloud Vulnerability Disclosure
Vulnerability disclosure
Salesforce Service Cloud APIs runs a coordinated vulnerability disclosure program on Hackerone.
CloudCRMCustomer ServiceEnterpriseSalesforceSupport
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-27'
method: searched
source: https://www.salesforce.com/company/disclosure/
program:
published: true
name: Salesforce Responsible Disclosure Policy
url: https://www.salesforce.com/company/disclosure/
http_status: 200
probed: '2026-08-27'
submission_url: https://sfdc.co/SubmitVuln
submission_http_status: 200
safe_harbor: true
safe_harbor_quote: >-
"Salesforce pledges not to initiate legal action against researchers for penetrating or
attempting to penetrate our systems as long as they adhere to this policy."
process_quote: >-
"share details of the suspected vulnerability with Salesforce by submitting the details at
https://sfdc.co/SubmitVuln ... Provide full details of the suspected vulnerability so the
Salesforce security team may validate and reproduce the issue"
testing_guidance_quote: >-
"Whenever a Trial or Developer Edition is available, please conduct all vulnerability testing
against such instances. Always use test or demo accounts when testing."
prohibited: >-
Actions that may negatively affect Salesforce or its users — spam, brute force, denial of
service — are expressly prohibited. A Security Assessment Agreement must be reviewed before testing.
agreements:
- name: Responsible Disclosure Policy
url: https://www.salesforce.com/company/disclosure/
- name: Security Assessment Agreement
url: https://www.salesforce.com/company/disclosure/
bug_bounty:
platform: null
url: null
note: >-
NOT CONFIRMED. hackerone.com/salesforce returns an HTTP 200 SPA shell but hackerone.com/salesforce.json
returns 404, so no public HackerOne program could be verified from the platform's own API, and the
disclosure policy page itself does not name a bounty platform or a reward table. Recorded as
unknown rather than claimed.
evidence:
- {url: 'https://hackerone.com/salesforce', status: 200, note: 'SPA shell, not a program page'}
- {url: 'https://hackerone.com/salesforce.json', status: 404}
security_txt:
served: false
probed:
- {url: 'https://www.salesforce.com/.well-known/security.txt', status: 302}
- {url: 'https://api.salesforce.com/.well-known/security.txt', status: 404}
- {url: 'https://login.salesforce.com/.well-known/security.txt', status: 404}
- {url: 'https://trust.salesforce.com/.well-known/security.txt', status: 404}
- {url: 'https://developer.salesforce.com/.well-known/security.txt', status: 403, note: bot challenge}
gap: >-
A company running a formal responsible-disclosure programme with a safe-harbour pledge publishes
no RFC 9116 security.txt on any of its primary hosts. Adding one at www.salesforce.com pointing
Policy: at /company/disclosure/ and Contact: at sfdc.co/SubmitVuln would be a one-file fix.
security_portal:
url: https://security.salesforce.com/
http_status: 200
probed: '2026-08-27'
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/service-cloud-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.