generated: '2026-09-13' method: searched source: >- https://docs.squared.ai/deployment-and-security/security-and-compliance/overview and https://github.com/Multiwoven/multiwoven/blob/main/SECURITY.md program: published: true type: email-intake bug_bounty: false platform: null safe_harbor_published: false policy_page: https://docs.squared.ai/deployment-and-security/security-and-compliance/overview contacts: - channel: email value: security@squared.ai scope: AI Squared platform source: https://docs.squared.ai/deployment-and-security/security-and-compliance/overview quote: >- "If you discover a security issue in this project, please report it by sending an email to security@squared.ai." - channel: email value: hello@multiwoven.com scope: Multiwoven open-source project source: https://github.com/Multiwoven/multiwoven/blob/main/SECURITY.md note: >- The repository SECURITY.md still routes to the pre-acquisition multiwoven.com address while the documentation routes to security@squared.ai. Two published addresses for the same codebase; a reporter has to pick. response_commitment: published: false quote: '"We will respond to your report as soon as possible and will work with you to address the issue."' note: No stated acknowledgement window, triage SLA, disclosure timeline or reward. security_txt: published: false probed: - url: https://aisquared.ai/.well-known/security.txt status: 404 - url: https://docs.squared.ai/.well-known/security.txt status: 404 - url: https://api.squared.ai/.well-known/security.txt status: 404 checked: '2026-09-13' note: >- RFC 9116 is not implemented on any host. The intake address exists only in prose on a docs page and in a repository SECURITY.md, so an automated scanner finds nothing.