SkyKick · Vulnerability Disclosure
Skykick Vulnerability Disclosure
Vulnerability disclosure
SkyKick runs a coordinated vulnerability disclosure program on Hackerone.
CompanyBackupMigrationMicrosoft-365Managed Service ProvidersSaaS SecurityCloud AutomationData ProtectionAzure API Management
Program: Hackerone
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
generated: '2026-08-28'
method: searched
source: https://www.connectwise.com/company/trust/security/vulnerability-disclosure-policy
note: >-
SkyKick serves no security.txt of its own — /.well-known/security.txt returned
404 on skykick.com and on every ConnectWise Cloud Services host (probed
2026-08-28). The disclosure program that covers the former SkyKick services is
the ConnectWise one, published in full and open to anonymous reports.
program:
present: true
type: coordinated vulnerability disclosure
bug_bounty: false
bounty_note: >-
"any reward is at the discretion of ConnectWise" — a discretionary
acknowledgement, not a bounty program. No HackerOne or Bugcrowd listing exists
(hackerone.com/connectwise and bugcrowd.com/connectwise both returned 404,
probed 2026-08-28).
policy_url: https://www.connectwise.com/company/trust/security/vulnerability-disclosure-policy
probed: '2026-08-28'
http_status: 200
reporting:
email: disclosure@connectwise.com
anonymous_reports_accepted: true
acknowledgement_sla: 3 business days (when contact information is provided)
incident_hotline:
name: Partner InfoSec Hotline
phone: 1-888-WISE911
email: securityincident@connectwise.com
purpose: active, urgent security incidents
safe_harbor:
present: true
text: >-
"If you make a good faith effort to comply with this policy during your
security research or discovery, we will consider your research to be
authorized... ConnectWise will not recommend or pursue legal action related
to your research."
required_report_contents:
- Clear description of the vulnerability and its potential impact
- Product, version and configuration of any software or hardware impacted
- Step-by-step reproduction instructions
- A proof-of-concept
- Suggested mitigation or remediation
publication:
advisories:
url: https://www.connectwise.com/company/trust/advisories
rss: https://www.connectwise.com/company/trust/advisories/rss
probed: '2026-08-28'
http_status: 200
security_bulletins:
url: https://www.connectwise.com/company/trust/security-bulletins
rss: https://www.connectwise.com/company/trust/security-bulletins/rss
probed: '2026-08-28'
http_status: 200
disclosure_repository:
url: https://github.com/ConnectWise-Advisories/Disclosures
probed: '2026-08-28'
http_status: 200
note: A public GitHub repository of ConnectWise-issued disclosures.
security_txt:
present: false
probed: '2026-08-28'
hosts_probed:
- host: skykick.com
status: 404
- host: apis.cloudservices.connectwise.com
status: 404
- host: skykick.developer.azure-api.net
status: 404
- host: developers.cloudservices.connectwise.com
status: 404
recommendation: >-
An RFC 9116 security.txt at apis.cloudservices.connectwise.com pointing at the
existing policy URL and disclosure@connectwise.com would make this program
machine-discoverable; today it is only findable by reading the Trust Center.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/skykick-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.