Super.com · Vulnerability Disclosure

Supercom Vulnerability Disclosure

Vulnerability disclosure

Super.com publishes an RFC 9116 security.txt at https://www.super.com/.well-known/security.txt naming a security contact and describing an invite-only Bugcrowd bug bounty program. There is no public program page: researchers are asked to email the contact first and are then invited in.

Super.com runs a coordinated vulnerability disclosure program on Bugcrowd. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

CompanyTravelHotelsBookingFlightsConsumer FinanceCash BackSavingsPrescription DiscountsMobile Applications
Program: Bugcrowd security.txt present

Disclosure Policy

Security Contact

Contact
mailto:security@super.com

Source

Vulnerability Disclosure

supercom-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-05'
method: searched
probe: true
source: https://www.super.com/.well-known/security.txt
name: Super.com vulnerability disclosure
description: >-
  Super.com publishes an RFC 9116 security.txt at https://www.super.com/.well-known/security.txt
  naming a security contact and describing an invite-only Bugcrowd bug bounty program. There is no
  public program page: researchers are asked to email the contact first and are then invited in.
security_txt:
  url: https://www.super.com/.well-known/security.txt
  status: 200
  file: ../well-known/supercom-security.txt
  fields:
    contact:
    - mailto:security@super.com
    expires: '2030-01-01T08:24:00Z'
    hiring: https://landing.super.com/careers
    preferred_languages: EN
    policy: null
    encryption: null
    acknowledgments: null
contact:
- mailto:security@super.com
bug_bounty:
  platform: Bugcrowd
  public_program_page: null
  access: invite-only
  intake: email security@super.com and request an invitation
  evidence: >-
    security.txt comment — "We have a BugCrowd program for security vulnerabilities: if you are
    reading this and have found a vulnerability, please email us and we can invite you to the
    program!"
  probed:
  - url: https://bugcrowd.com/super-com
    status: 404
  - url: https://bugcrowd.com/engagements/super-com
    status: 404
  - url: https://bugcrowd.com/snaptravel
    status: 404
policy_page: null
evidence:
- source: https://www.super.com/.well-known/security.txt
  status: 200
  fetched: '2026-08-05'
  kind: RFC 9116 security.txt
gaps:
- >-
  No Policy: field in security.txt — no linked disclosure policy or safe-harbor statement.
- >-
  No public Bugcrowd program page resolves; scope, rewards, and safe harbor are not publicly stated.