generated: '2026-08-02' method: searched probe: true source: https://abnormal.ai/legal/disclosure description: >- Abnormal AI publishes a Responsible Disclosure Policy at abnormal.ai/legal/disclosure (reachable from the trust center at security.abnormal.ai). Reports are submitted through a form on that page, with security@abnormal.ai as the direct contact. Abnormal commits to acknowledging a report within five (5) business days. There is no public bug bounty program (no HackerOne, Bugcrowd or Intigriti listing was found) and no published PGP key. No /.well-known/security.txt (RFC 9116) is served on any Abnormal host — see well-known/abnormal-well-known.yml for the probe results. policy: - https://abnormal.ai/legal/disclosure contact: - mailto:security@abnormal.ai - https://abnormal.ai/legal/disclosure program: bug_bounty: false bounty_platform: null safe_harbor_language: >- Researchers are asked to make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Abnormal service, and to test only systems they own or have explicit permission to test. acknowledgement_sla: 5 business days out_of_scope: - denial of service / DDoS - spamming - social engineering of Abnormal employees - attacks against physical infrastructure owner: CISO security_txt: present: false probed_hosts: - https://abnormal.ai/.well-known/security.txt - https://api.abnormalplatform.com/.well-known/security.txt - https://security.abnormal.ai/.well-known/security.txt - https://portal.abnormalsecurity.com/.well-known/security.txt evidence: - source: https://abnormal.ai/legal/disclosure kind: responsible disclosure policy page http_status: 200 fetched: '2026-08-02' - source: https://security.abnormal.ai/ kind: trust center links to the disclosure page http_status: 200 fetched: '2026-08-02'