SkyKick · Vulnerability Disclosure

Skykick Vulnerability Disclosure

Vulnerability disclosure

SkyKick runs a coordinated vulnerability disclosure program on Hackerone.

CompanyBackupMigrationMicrosoft-365Managed Service ProvidersSaaS SecurityCloud AutomationData ProtectionAzure API Management
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

skykick-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-28'
method: searched
source: https://www.connectwise.com/company/trust/security/vulnerability-disclosure-policy
note: >-
  SkyKick serves no security.txt of its own — /.well-known/security.txt returned
  404 on skykick.com and on every ConnectWise Cloud Services host (probed
  2026-08-28). The disclosure program that covers the former SkyKick services is
  the ConnectWise one, published in full and open to anonymous reports.
program:
  present: true
  type: coordinated vulnerability disclosure
  bug_bounty: false
  bounty_note: >-
    "any reward is at the discretion of ConnectWise" — a discretionary
    acknowledgement, not a bounty program. No HackerOne or Bugcrowd listing exists
    (hackerone.com/connectwise and bugcrowd.com/connectwise both returned 404,
    probed 2026-08-28).
  policy_url: https://www.connectwise.com/company/trust/security/vulnerability-disclosure-policy
  probed: '2026-08-28'
  http_status: 200
  reporting:
    email: disclosure@connectwise.com
    anonymous_reports_accepted: true
    acknowledgement_sla: 3 business days (when contact information is provided)
  incident_hotline:
    name: Partner InfoSec Hotline
    phone: 1-888-WISE911
    email: securityincident@connectwise.com
    purpose: active, urgent security incidents
  safe_harbor:
    present: true
    text: >-
      "If you make a good faith effort to comply with this policy during your
      security research or discovery, we will consider your research to be
      authorized... ConnectWise will not recommend or pursue legal action related
      to your research."
  required_report_contents:
  - Clear description of the vulnerability and its potential impact
  - Product, version and configuration of any software or hardware impacted
  - Step-by-step reproduction instructions
  - A proof-of-concept
  - Suggested mitigation or remediation
publication:
  advisories:
    url: https://www.connectwise.com/company/trust/advisories
    rss: https://www.connectwise.com/company/trust/advisories/rss
    probed: '2026-08-28'
    http_status: 200
  security_bulletins:
    url: https://www.connectwise.com/company/trust/security-bulletins
    rss: https://www.connectwise.com/company/trust/security-bulletins/rss
    probed: '2026-08-28'
    http_status: 200
  disclosure_repository:
    url: https://github.com/ConnectWise-Advisories/Disclosures
    probed: '2026-08-28'
    http_status: 200
    note: A public GitHub repository of ConnectWise-issued disclosures.
security_txt:
  present: false
  probed: '2026-08-28'
  hosts_probed:
  - host: skykick.com
    status: 404
  - host: apis.cloudservices.connectwise.com
    status: 404
  - host: skykick.developer.azure-api.net
    status: 404
  - host: developers.cloudservices.connectwise.com
    status: 404
  recommendation: >-
    An RFC 9116 security.txt at apis.cloudservices.connectwise.com pointing at the
    existing policy URL and disclosure@connectwise.com would make this program
    machine-discoverable; today it is only findable by reading the Trust Center.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/skykick-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.