generated: '2026-09-14' method: searched source: https://aignostics.readthedocs.io/en/latest/security.html scope: >- The published policy covers the Aignostics Python SDK (the open-source client), not explicitly the Aignostics Platform service. No separate platform-level disclosure policy was found. program: published: true url: https://aignostics.readthedocs.io/en/latest/security.html http_status: 200 intake: - channel: github-security-advisory url: https://github.com/aignostics/python-sdk/security/advisories/new http_status: 200 note: >- Private vulnerability reporting is enabled on the repository, which is the intake the policy names first. - channel: email address: helmut@aignostics.com note: >- A named individual rather than a role address. security@aignostics.com was not published and no /.well-known/security.txt is served on any Aignostics host. commitments: - confirm receipt of the report - investigate - fix - release a security update response_sla: not stated safe_harbor: not stated bug_bounty: exists: false detail: >- No HackerOne, Bugcrowd, Intigriti or self-hosted bounty program was found; the policy does not mention rewards. supported_versions: statement: We currently provide security updates for the latest minor version. scope: Aignostics Python SDK security_txt: served: false probed: - url: https://www.aignostics.com/.well-known/security.txt status: 404 - url: https://aignostics.com/.well-known/security.txt status: 404 - url: https://platform.aignostics.com/.well-known/security.txt status: 307 note: Auth0 session gate; no anonymous document - url: https://aignostics.readthedocs.io/.well-known/security.txt status: 404 note: >- A one-line RFC 9116 file on www.aignostics.com pointing Policy: at the existing security.html and Contact: at the existing mailbox would make this program machine-discoverable at zero cost. The program already exists; only the pointer is missing. supply_chain_practice: source: >- https://aignostics.readthedocs.io/en/latest/security.html, https://aignostics.readthedocs.io/en/latest/operational_excellence.html controls: - Dependabot - Renovate - GitHub CodeQL - SonarQube - secret detection - pip-audit - trivy - SBOM generation note: >- Unusually complete for a company of this size, and published rather than asserted - the CI configuration backing these claims is in the public repository.