generated: '2026-09-12' method: searched probe: true source: https://www.agilix.com/security name: Agilix Labs vulnerability disclosure description: >- Agilix publishes a security page that names a route for reporting security issues, but it is a support address rather than a formal coordinated-disclosure program. There is no published policy document, no safe-harbour statement, no scope definition, no bug bounty, and no RFC 9116 security.txt — /.well-known/security.txt returned 404 on all six Agilix hosts probed on 2026-09-12. A researcher with a finding has an address to write to and nothing else to go on. policy_url: https://www.agilix.com/security contacts: - email: security@agilix.com context: >- Named on the security page for prospective customers requesting SOC 2 information and annual penetration-testing results. - email: support@agilix.com context: Named on the security page as the route for reporting a security issue. security_txt: published: false probed: - url: https://www.agilix.com/.well-known/security.txt status: 404 - url: https://agilix.com/.well-known/security.txt status: 404 - url: https://api.agilixbuzz.com/.well-known/security.txt status: 404 - url: https://backgroundapi.agilixbuzz.com/.well-known/security.txt status: 404 - url: https://agilixbuzz.com/.well-known/security.txt status: 404 - url: https://support.agilix.com/.well-known/security.txt status: 404 checked: '2026-09-12' bug_bounty: program: null platforms_checked: [HackerOne, Bugcrowd, Intigriti] found: false safe_harbour: not published disclosure_policy_document: not published scope_definition: not published penetration_testing: performed: true cadence: annual results_public: false request_url: https://www.agilix.com/pentest note: >- The security page carries a "Request Our Annual Penetration Testing Results" call to action pointing at https://www.agilix.com/pentest (HTTP 200). The results themselves are gated behind a request form; no summary or attestation is published openly. evidence: - source: https://www.agilix.com/security status: 200 kind: disclosure page keywords: - report a security - security issue - security@ - source: https://www.agilix.com/pentest status: 200 kind: penetration test request page gaps: - No /.well-known/security.txt on any host — the single cheapest fix available here. - No published disclosure policy, scope, or safe harbour for researchers. - Security reports are routed to general support rather than to a security-specific intake.