Salesforce Service Cloud APIs · Vulnerability Disclosure

Service Cloud Vulnerability Disclosure

Vulnerability disclosure

Salesforce Service Cloud APIs runs a coordinated vulnerability disclosure program on Hackerone.

CloudCRMCustomer ServiceEnterpriseSalesforceSupport
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-27'
method: searched
source: https://www.salesforce.com/company/disclosure/
program:
  published: true
  name: Salesforce Responsible Disclosure Policy
  url: https://www.salesforce.com/company/disclosure/
  http_status: 200
  probed: '2026-08-27'
  submission_url: https://sfdc.co/SubmitVuln
  submission_http_status: 200
  safe_harbor: true
  safe_harbor_quote: >-
    "Salesforce pledges not to initiate legal action against researchers for penetrating or
    attempting to penetrate our systems as long as they adhere to this policy."
  process_quote: >-
    "share details of the suspected vulnerability with Salesforce by submitting the details at
    https://sfdc.co/SubmitVuln ... Provide full details of the suspected vulnerability so the
    Salesforce security team may validate and reproduce the issue"
  testing_guidance_quote: >-
    "Whenever a Trial or Developer Edition is available, please conduct all vulnerability testing
    against such instances. Always use test or demo accounts when testing."
  prohibited: >-
    Actions that may negatively affect Salesforce or its users — spam, brute force, denial of
    service — are expressly prohibited. A Security Assessment Agreement must be reviewed before testing.
  agreements:
    - name: Responsible Disclosure Policy
      url: https://www.salesforce.com/company/disclosure/
    - name: Security Assessment Agreement
      url: https://www.salesforce.com/company/disclosure/
bug_bounty:
  platform: null
  url: null
  note: >-
    NOT CONFIRMED. hackerone.com/salesforce returns an HTTP 200 SPA shell but hackerone.com/salesforce.json
    returns 404, so no public HackerOne program could be verified from the platform's own API, and the
    disclosure policy page itself does not name a bounty platform or a reward table. Recorded as
    unknown rather than claimed.
  evidence:
    - {url: 'https://hackerone.com/salesforce', status: 200, note: 'SPA shell, not a program page'}
    - {url: 'https://hackerone.com/salesforce.json', status: 404}
security_txt:
  served: false
  probed:
    - {url: 'https://www.salesforce.com/.well-known/security.txt', status: 302}
    - {url: 'https://api.salesforce.com/.well-known/security.txt', status: 404}
    - {url: 'https://login.salesforce.com/.well-known/security.txt', status: 404}
    - {url: 'https://trust.salesforce.com/.well-known/security.txt', status: 404}
    - {url: 'https://developer.salesforce.com/.well-known/security.txt', status: 403, note: bot challenge}
  gap: >-
    A company running a formal responsible-disclosure programme with a safe-harbour pledge publishes
    no RFC 9116 security.txt on any of its primary hosts. Adding one at www.salesforce.com pointing
    Policy: at /company/disclosure/ and Contact: at sfdc.co/SubmitVuln would be a one-file fix.
security_portal:
  url: https://security.salesforce.com/
  http_status: 200
  probed: '2026-08-27'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/service-cloud-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.