Spekit · Vulnerability Disclosure

Spekit Vulnerability Disclosure

Vulnerability disclosure

Spekit runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanySaasSales EnablementRevenue EnablementDigital AdoptionKnowledge ManagementMCPArtificial IntelligenceAnalyticsSalesContent ManagementAgentsOAuth
Program: Hackerone

Disclosure Policy

Policy

Security Contact

Contact
security@spekit.co
Contact
infra+security@spekit.co

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.spekit.com/vulnerability-disclosure-program
policy:
- https://www.spekit.com/vulnerability-disclosure-program
contact:
- security@spekit.co
- infra+security@spekit.co
contact_source: >-
  Both addresses are published by Spekit in DNS, as CAA iodef records on spekit.com and
  spekit.co: `0 iodef "mailto:security@spekit.co"` and `0 iodef "mailto:infra+security@spekit.co"`.
  The disclosure page itself takes submissions through a web form rather than an email address.
bug_bounty: false
bug_bounty_note: >-
  No HackerOne, Bugcrowd or Intigriti program was found, and the policy page offers no bounty —
  it is an unpaid coordinated-disclosure program with a submission form.
program:
  name: Spekit Vulnerability Disclosure Policy
  submission: web form on the policy page (email address, location of vulnerability, description, CVSS/score/type, date observed, screenshot upload up to 10MB)
  location_options: [Chrome Browser Extension, Web App, Webpage, IP, Other]
  commitments:
  - Maintain trust and confidentiality with reporting researchers.
  - Work with the reporter to validate and remediate reported vulnerabilities.
  - Investigate and remediate consistent with protecting cloud-customer safety and security.
  - Remediation time varies with severity and affected systems.
  researcher_obligations:
  - Do not disclose submission details without express written permission.
  - Provide clear reproduction steps.
  - Stay inside the scope below.
  - Include an email address so Spekit can follow up.
  out_of_scope:
  - Physical security of offices, employees, equipment
  - Social engineering and phishing
  - DoS/DDoS or any testing that impacts operation of Spekit systems
  - Accessing, downloading or modifying data in an account that is not yours
  - Testing that results in spam or unsolicited messages
  - Testing third-party applications or services
  - Defacing any Spekit asset
  safe_harbor_stated: false
security_txt: false
security_txt_note: >-
  No /.well-known/security.txt is served on any Spekit host (404 on spekit.com,
  www.spekit.com, help.spekit.com and mcp.spekit.co; api.spekit.co and app.spekit.co answer 200
  with an SPA HTML shell, which is not a document). Publishing RFC 9116 security.txt pointing at
  this policy page would make the program machine-discoverable — it is currently only reachable
  by following a footer link from https://www.spekit.com/security.
evidence:
- source: https://www.spekit.com/vulnerability-disclosure-program
  kind: disclosure-policy-page
  http_status: 200
  checked: '2026-08-14'
- source: https://www.spekit.com/security
  kind: referring-page
  http_status: 200
- source: dig CAA spekit.com / spekit.co
  kind: dns-iodef