generated: '2026-08-13' method: searched source: https://trust.uniphore.com/ name: ActionIQ Vulnerability Disclosure (Uniphore) description: >- ActionIQ serves no security.txt on any of its own hosts. A published responsible-disclosure channel does exist, on the parent brand: the SafeBase-hosted Uniphore trust center carries an explicit "If you think you may have discovered a vulnerability, please send us a note" path that resolves to a responsible-disclosure mailto. ActionIQ is sold as Uniphore's CDP Agent and actioniq.com 301-redirects to www.uniphore.com/actioniq/, which is why the parent-brand channel is the correct one to record here. program: exists: true type: responsible-disclosure operator: Uniphore bug_bounty: false platform: null policy_url: https://trust.uniphore.com/ report_channel: mailto:uniphore_trust@uniphore.com report_subject: SafeBase Responsible Disclosure Report for Uniphore contact_email: uniphore_trust@uniphore.com safe_harbor_published: false scope_published: false rewards: false security_txt: served: false probes: - url: https://www.actioniq.com/.well-known/security.txt status: 404 - url: https://actioniq.com/.well-known/security.txt status: 404 - url: https://api.actioniq.com/.well-known/security.txt status: 403 - url: https://www.uniphore.com/.well-known/security.txt status: 404 supporting_practices: source: https://www.uniphore.com/security/ published: - Network vulnerability scanning - Annual third-party penetration tests across production and corporate networks - Vulnerability and patch management with prioritized critical/high patching - Security Incident Event Management (SIEM) x-evidence: fetched: '2026-08-13' urls: - url: https://trust.uniphore.com/ status: 200 - url: https://www.uniphore.com/security/ status: 200 notes: >- No RFC 9116 security.txt is published, and no bug-bounty program (HackerOne, Bugcrowd, Intigriti) was found for either ActionIQ or Uniphore. The disclosure channel is a trust-center mailto only; there is no published safe-harbor statement or scope definition.