UserGems · Vulnerability Disclosure

Usergems Vulnerability Disclosure

Vulnerability disclosure

UserGems runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

Sales IntelligenceOutboundAccount Based MarketingChampion TrackingJob ChangesBuying SignalsAI ScoringSales EngagementCRMRevenue OperationsGo-To-MarketMCPAI Agents
Program: Hackerone security.txt present

Disclosure Policy

Policy
Policy

Security Contact

Contact
security@usergems.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.usergems.com/legal-security/security
policy:
  - https://www.usergems.com/legal-security/security
  - https://trust.usergems.com
contact:
  - security@usergems.com
response_commitment: >-
  "we will get back to you within 24 hours, and usually earlier"
coordinated_disclosure: >-
  UserGems asks reporters not to publicly disclose an issue until it has been
  addressed.
policy_text: >-
  "Disclosure — If you believe you've discovered a bug in UserGems' security,
  please get in touch at security@usergems.com and we will get back to you within
  24 hours, and usually earlier. We request that you not publicly disclose the
  issue until we have addressed it."
bug_bounty:
  program: none
  platform: null
  note: >-
    No HackerOne, Bugcrowd or Intigriti program was found. Disclosure is by email
    to security@usergems.com only.
security_txt:
  published: false
  note: >-
    /.well-known/security.txt returns 404 on www, app, api and help hosts, so the
    policy is reachable by a human but not by a machine at the RFC 9116 location.
    Publishing one is the cheapest single improvement available on this surface.
testing_program:
  penetration_testing: >-
    "we contract an independent third-party to conduct penetration testing
    whenever there are major changes to our application and at least annually"
  continuous: >-
    "continuous network vulnerability testing" plus automated continuous
    compliance monitoring
  document: Application Penetration Testing (available via trust.usergems.com)
evidence:
  - source: https://www.usergems.com/legal-security/security
    kind: disclosure page
    http_status: 200
    keywords:
      - disclosure
      - vulnerability
      - security@usergems.com
      - penetration testing
  - source: https://trust.usergems.com
    kind: trust center
    http_status: 200
    keywords:
      - Responsible Disclosure
      - Application Penetration Testing
  - source: https://www.usergems.com/.well-known/security.txt
    kind: security.txt
    http_status: 404