generated: '2026-09-05' method: probed source: probe of /.well-known/security.txt across all ten known AAICO/Opus hosts published: false note: >- AAICO publishes NO vulnerability disclosure programme that a researcher can find by the standard routes. /.well-known/security.txt returns 404 on every host probed (aaico.com, www.aaico.com, opus.com, www.opus.com, developer.opus.com, operator.opus.com, status.opus.com, files.opus.com) and returns the SPA HTML shell — not a document — on app.opus.com and trust.opus.com. No security@ contact, disclosure policy page, or bug-bounty programme (HackerOne / Bugcrowd / Intigriti) was found. A Vanta trust center exists at trust.opus.com and is the only published security-contact surface, but it is client-rendered and advertises no disclosure policy in its served HTML. security_txt: false bug_bounty: false bounty_platform: null disclosure_policy_url: null security_contact: null x-evidence: - url: https://www.opus.com/.well-known/security.txt status: 404 fetched: '2026-09-05' - url: https://developer.opus.com/.well-known/security.txt status: 404 fetched: '2026-09-05' - url: https://operator.opus.com/.well-known/security.txt status: 404 fetched: '2026-09-05' - url: https://www.aaico.com/.well-known/security.txt status: 404 fetched: '2026-09-05' - url: https://trust.opus.com/.well-known/security.txt status: 200 fetched: '2026-09-05' note: 200 returns the Vanta SPA HTML shell for every /.well-known/* path — a catch-all, not a security.txt. recommendation: >- For a company holding SOC 2 Type II and ISO 27001 and selling into banking, insurance and healthcare, an RFC 9116 security.txt on opus.com and aaico.com is the single cheapest gap to close here.