generated: '2026-09-19' method: searched source: https://github.com/lugdwei/AgentMesh-Public/blob/main/SECURITY.md corroboration: probe-security-programs.py (vdp=none trust=none — it reads security.txt and site paths, not GitHub) and live probes 2026-09-19 checked: '2026-09-19' summary: >- AgentMesh publishes a short security policy in its public GitHub repository and nothing on its own host: no RFC 9116 security.txt, no /security or /trust page, no bug bounty, no safe-harbour statement, no response-time commitment. The policy's substance is one instruction — report privately through GitHub's private vulnerability reporting / Security Advisory mechanism for the repository "when available", and never post exploit details or credentials in a public issue. That is a real, published disclosure channel, so a Security pointer is emitted; a reader should know it is the thinnest form the check accepts and that it lives on GitHub rather than on the service. published: true policy: url: https://github.com/lugdwei/AgentMesh-Public/blob/main/SECURITY.md raw: https://raw.githubusercontent.com/lugdwei/AgentMesh-Public/main/SECURITY.md status: 200 title: Security Policy added: '2026-09-06 (commit "docs: add public security policy")' reporting_channel: GitHub private vulnerability reporting / Security Advisory on lugdwei/AgentMesh-Public reporting_verbatim: >- "Do not publish exploitable vulnerability details or credentials in a public issue. Use GitHub's private vulnerability reporting / Security Advisory mechanism for this repository when available. Include enough information to reproduce the issue without including live secrets or personal data." scope_verbatim: >- "This repository is the public developer portal and documentation surface. The AgentMesh production backend and its private source history are intentionally not published here." scope_note: >- The policy scopes ITSELF to the documentation repository, and the production service is explicitly out of that repository. Whether a report about app.agentmesh.link (the live API) is in scope is not stated; the GitHub advisory channel is nonetheless the only reporting path published anywhere. private_reporting_enabled: unverified private_reporting_note: >- Whether GitHub private vulnerability reporting is actually switched on for the repository is not observable anonymously ("when available" in the policy suggests it may not be). Not claimed. response_time: not-published safe_harbour: false in_scope_out_of_scope: not-published secrets_hygiene_rule: 'Never submit API keys, agent credentials, access tokens, Stripe secrets, webhook signing secrets, private keys, passwords, environment files or database dumps.' contact: security_email: not-published general_contact: 'One address on /terms and /privacy (Cloudflare email-protected; not reproduced here). Not designated for security.' rfc9116: served: false probes: - {url: 'https://app.agentmesh.link/.well-known/security.txt', status: 404} - {url: 'https://agentmesh.link/.well-known/security.txt', status: 0, error: 'Could not resolve host'} fix: 'Serving a security.txt with Contact: the GitHub advisory URL and a Policy: line pointing at SECURITY.md is a one-file change that would make the channel discoverable from the service itself.' site_pages: probes: - {url: 'https://app.agentmesh.link/security', status: 404} - {url: 'https://app.agentmesh.link/trust', status: 404} - {url: 'https://app.agentmesh.link/.well-known/security.txt', status: 404} bug_bounty: published: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] result: none found intigriti_note: >- https://app.intigriti.com/programs/agentmesh answers 200, but so does a negative-control program path (zzz-no-such-program-7f3ab91c) with a byte-identical 251,569-byte SPA shell, so the 200 is the app shell and not a program. Recorded so a later round does not credit it. Any real Intigriti/HackerOne program named "agentmesh" would also need to be tied to THIS provider — three unrelated products share the name. trust_center: present: false probes: [{url: 'https://app.agentmesh.link/trust', status: 404}] note: 'No trust-center artifact is written and no TrustCenter or Compliance pointer is emitted.' security_headers_observed: host: https://app.agentmesh.link hsts: absent content_security_policy: absent x_frame_options: absent x_content_type_options: absent note: 'From a HEAD of the homepage on 2026-09-19; only Cloudflare edge headers present. TLS 1.3, cert to 2026-12-04 (see agentmesh-link-domain-security.yml). DNSSEC, CAA, SPF and DMARC are all absent on agentmesh.link.' pointer_basis: >- `Security` (security_disclosure) is emitted on the strength of the published SECURITY.md with a named private reporting channel. `SecurityTxt`, `TrustCenter` and `Compliance` are NOT emitted. cross_links: domain_security: security/agentmesh-link-domain-security.yml well_known: well-known/agentmesh-link-well-known.yml regulatory: regulatory/agentmesh-link-regulatory-posture.yml