generated: '2026-09-12' method: searched source: https://trust.agentifai.com/ program: published: true name: Responsible Disclosure url: https://trust.agentifai.com/ location: >- Published as a "Responsible Disclosure" control under the App Security section of the AgentifAI SafeBase trust center. The policy itself opens as a trust-center item (itemUid=64c9680b-ef79-4c92-baa0-13b541954bef) rather than at a standalone URL. type: responsible-disclosure bug_bounty: false bounty_platform: null safe_harbor: unknown security_txt: published: false probed: - url: https://www.agentifai.com/.well-known/security.txt status: 404 - url: https://agentifai.com/.well-known/security.txt status: 404 - url: https://careers.agentifai.com/.well-known/security.txt status: 404 - url: https://trust.agentifai.com/.well-known/security.txt status: 403 note: >- No RFC 9116 security.txt is served on any host AgentifAI controls. The disclosure policy exists but is only reachable through the trust center UI, so a machine cannot find it from the domain root. This is the one concrete, low-cost fix available to this provider: publish /.well-known/security.txt on agentifai.com with a Policy: line pointing at the trust center item and a Contact: line for the security address. contact: published: true channel: trust-center note: >- A security contact is displayed on the trust center; the value was returned obfuscated and is deliberately not asserted here. evidence: - url: https://trust.agentifai.com/ status: 403 note: Cloudflare challenge on raw fetch; content confirmed via a rendering fetch.