You should check if the software is listed on the bugcrowd bug bounty list. Its a list of websites and software which accept responsible disclosure of security issues.
http://bugcrowd.com/list-of-bug-bounty-programs/
If you can't find it there you should send them an email and suggest they add it.