Stack Moxie · Vulnerability Disclosure

Stack Moxie Vulnerability Disclosure

Vulnerability disclosure

Stack Moxie runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyRevOpsMarketing OperationsObservabilityMonitoringTestingTest AutomationQA AutomationMarketing AutomationEmail DeliverabilitySalesforceMarketogRPCSaaS
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
https://www.stackmoxie.com/support/

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-14'
method: searched
probe: true
source: https://www.stackmoxie.com/security/
policy:
- https://www.stackmoxie.com/security/
program: bug-bounty
contact:
- https://www.stackmoxie.com/support/
security_txt: false
detail: >-
  Stack Moxie runs a crowd-sourced bug-bounty program with rewards for reporting
  potential flaws, alongside recurring third-party penetration tests, static code
  analysis, and infrastructure vulnerability scans. There is no published bounty
  platform (no HackerOne/Bugcrowd/Intigriti page), no security@ address, and no
  /.well-known/security.txt on any host - reporters are told to use the contact
  form on the security page or the support page, so there is no machine-readable
  intake and no stated response or safe-harbor terms.
gaps:
- no /.well-known/security.txt (RFC 9116) on any Stack Moxie host
- no published disclosure SLA or safe-harbor statement
- no dedicated security contact address; intake is a marketing contact form
evidence:
- source: https://www.stackmoxie.com/security/
  kind: disclosure page
  keywords:
  - vulnerability
  - bug bounty
  - penetration testing
  - static code analysis
- source: well-known/stack-moxie-well-known.yml
  kind: security.txt probe
  result: 404 on stackmoxie.com, www.stackmoxie.com, app.stackmoxie.com