generated: '2026-09-19' method: searched source: https://aicomglobal.com/security probed: - {url: 'https://aicomglobal.com/security', status: 200, content_type: text/html, fetched: '2026-09-19'} - {url: 'https://aicomglobal.com/.well-known/security.txt', status: 404, fetched: '2026-09-19'} - {url: 'https://aicomglobal.com/security.txt', status: 404, fetched: '2026-09-19'} - {url: 'https://aicomglobal.onrender.com/.well-known/security.txt', status: 404, fetched: '2026-09-19'} program: type: vulnerability-disclosure-policy page: https://aicomglobal.com/security contact: moonspacenow@gmail.com contact_type: email acknowledgement_sla: 48 hours fix_commitment: severity-driven timeline safe_harbour: true credit: optional, in the changelog bug_bounty: false platform: none (no HackerOne / Bugcrowd / Intigriti program found) security_txt: false quote: >- "Report a vulnerability — Email moonspacenow@gmail.com with steps to reproduce. We acknowledge within 48 hours, fix on a severity-driven timeline, and credit you in the changelog if you want the credit. No legal threats for good-faith research — ever." posture_statements: audits: >- "Two full adversarial audits (2026-06-16 and 2026-06-21, multi-agent review with every finding independently refuted or fixed) — every actioned finding closed and deployed. No known high/critical exploitable defect in aicomglobal's own code." controls_named: - x402 settle/verify gate precedes every signed artifact; a nonce CAS guard prevents double-charges - The Annal hash-chain is independently recomputable (live integrity check on /status) - Third-party content is data, never instructions — one escaping chokepoint for HTML, injection-scan framing on listing content, control-character stripping at intake - Outbound probing is SSRF-hardened — DNS+IP re-checks, per-host budgets, redirect guards, consent-gating (probe policy) - Dependency reachability analysis published in SECURITY.md (the repository it lives in is not publicly reachable — github.com/moonspacenow-tech/aicomglobal 404) key_governance: https://aicomglobal.com/about — Ed25519 signing key, env-pinned, kid bound into every signed artifact, public key history at /.well-known/aicom-pubkey, rotation-on-compromise policy (KEY-GOVERNANCE.md, not publicly reachable) note: >- A real disclosure policy with the substance the Security pointer requires — a named contact, an acknowledgement SLA, a fix commitment and an explicit safe-harbour statement — published as HTML rather than RFC 9116. probe-security-programs.py reported vdp=none because it keys on security.txt and bounty platforms; this file upgrades that result from the page itself. The audits are self-reported by the operator ("multi-agent review"); no third-party auditor, SOC 2, ISO 27001 or similar certification is named anywhere on the site, so no trust-center artifact and no Compliance pointer are emitted.