generated: '2026-07-25' method: searched probe: true source: https://github.com/adunaglobal/.github/blob/main/profile/README.md policy: [https://github.com/adunaglobal] contact: [] program: none bug_bounty: false security_txt: false statement: >- "Security — If you discover a security vulnerability in any Aduna repository, please report it responsibly via the contact information provided in the relevant repository." note: >- This is the only responsible-disclosure instruction Aduna publishes, and it is scoped to its GitHub repositories rather than to the Aduna platform or the CAMARA APIs it aggregates. There is no security@ address, no /.well-known/security.txt (404 on adunaglobal.com), no dedicated disclosure page (/security/ returns 404), and no HackerOne, Bugcrowd or Intigriti program. The automated probe (0-working/probe-security-programs.py) returned vdp=none trust=none; this record exists because the organisation profile statement is real, first-party and verifiable, and it is deliberately recorded as thin. evidence: - {source: 'https://github.com/adunaglobal/.github/blob/main/profile/README.md', kind: organisation profile security section} - {source: 'https://adunaglobal.com/.well-known/security.txt', kind: probe, status: 404} - {source: 'https://adunaglobal.com/security/', kind: probe, status: 404} escalation_alternative: url: https://adunaglobal.com/contact-us/ note: The general contact form is the only non-repository route to Aduna.