generated: '2026-09-09' method: searched probe: true source: https://docs.aembit.io/get-started/security-posture/security-compliance/ policy: [] contact: - mailto:security@aembit.io evidence: - source: https://docs.aembit.io/get-started/security-posture/security-compliance/ kind: docs-security-page status: 200 quote: 'For detailed control mappings and compliance reports, visit the Aembit Trust Center or contact security@aembit.io.' - source: https://trust.aembit.io/ kind: trust-center status: 200 note: SafeBase-hosted trust center listing SOC 2, ISO/IEC 27001, penetration test reports and CAIQ Lite behind an access request. findings: security_txt: false security_txt_note: >- NO FIRST-PARTY security.txt EXISTS. /.well-known/security.txt returned 404 on aembit.io, www.aembit.io, docs.aembit.io, trust.aembit.io and support.aembit.io. The only 200 in the catalog for this provider is on status.aembit.io and it is Atlassian Statuspage's own PGP-signed file (Canonical https://www.atlassian.com/.well-known/security.txt), which reports to Atlassian, not to Aembit. It is recorded in well-known/ as vendor-operated and is not counted here. bug_bounty: false bug_bounty_note: No HackerOne, Bugcrowd or Intigriti program found for aembit.io. dedicated_disclosure_page: false dedicated_disclosure_page_note: >- /security/, /responsible-disclosure/, /vulnerability-disclosure/ and /security-policy/ all returned 404 on aembit.io. published_security_contact: true penetration_testing: >- Documented as a recurring program — "Independent security firms conduct routine penetration tests" — with an Application Penetration Testing report available through the trust center. gap: summary: >- Aembit publishes a security contact and a certified compliance program but no machine-readable or navigable vulnerability-disclosure path. An RFC 9116 /.well-known/security.txt on aembit.io and docs.aembit.io, plus a linked disclosure policy, would be a small change that closes the gap for a security vendor whose own product category is credential hygiene.