generated: '2026-08-13' method: searched source: https://www.1mind.com/bug-bounty-program (HTTP 200) name: 1mind Bug Bounty Program policy_url: https://www.1mind.com/bug-bounty-program contact: security@1mind.com contact_method: email platform: self-hosted platform_note: Not run on HackerOne, Bugcrowd or Intigriti — reports go directly to security@1mind.com with the subject line "Bug Bounty Program". scope: >- "A security-related issue with 1mind's online systems." No explicit in-scope / out-of-scope asset list is published. submission_requirements: - A detailed description of the issue. - The steps required to reproduce it. - A good-faith effort to protect users' privacy and data while testing. disclosure_model: coordinated disclosure_note: 1mind asks researchers for responsible disclosure — report to 1mind before any public disclosure. safe_harbor: not-published response_sla: not-published rewards: not-published rewards_note: The page is titled a bug bounty program but publishes no bounty amounts, reward table or payout policy. security_txt: published: false probed: - url: https://www.1mind.com/.well-known/security.txt status: 404 - url: https://auth.1mind.com/.well-known/security.txt status: 404 note: >- 1mind has a working disclosure channel but does not advertise it at the RFC 9116 location. Publishing /.well-known/security.txt with Contact: mailto:security@1mind.com and Policy: https://www.1mind.com/bug-bounty-program would make the existing program machine-discoverable at zero cost. related: trust_center: 1mind-trust-center.yml domain_security: 1mind-domain-security.yml penetration_testing: >- Web-application and AI (OWASP Top 10 for LLM & ML) penetration testing is performed by Astra Security; reports are available through the Trust Center under NDA. See 1mind-trust-center.yml. privacy_contact: privacy@1mind.com privacy_request_url: https://www.1mind.com/privacy-and-data-access-request