Surfe · Vulnerability Disclosure
Surfe Vulnerability Disclosure
Vulnerability disclosure
Surfe publishes a written vulnerability-reporting policy — but on its GitHub organisation, not on surfe.com. SECURITY.md in the official `surfer` CLI repository names a private reporting channel, an acknowledgement target, and explicitly extends its scope to the Surfe API itself. There is no /.well-known/security.txt on any Surfe host and no bug bounty programme.
Surfe runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.
B2B DataContact DataSales IntelligenceEnrichmentLead GenerationCRMProspecting
Program: Hackerone
Disclosure Policy
Security Contact
Contact
security@surfe.com
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.