generated: '2026-09-14' method: probed source: >- /.well-known/security.txt probed on aiola.ai, www.aiola.ai, docs.aiola.ai, apis.aiola.ai, auth.aiola.ai and platform.aiola.ai; aiola.ai/security/ and the Trust Center also checked published: false security_txt: false bug_bounty: false disclosure_page: false security_contact: null evidence: - url: https://aiola.ai/.well-known/security.txt status: 404 - url: https://www.aiola.ai/.well-known/security.txt status: 404 - url: https://docs.aiola.ai/.well-known/security.txt status: 404 - url: https://aiola.ai/security/ status: 404 - url: https://trust.aiola.ai/ status: 200 detail: >- A Scytale Trust Center with SOC 2 Type II and ISO 27001:2022, but its public page data carries no security-contact, disclosure policy, or bug-bounty entry. note: >- aiOla holds two implemented security certifications and still publishes no route for a researcher to report a vulnerability — no security.txt on any host, no /security page, no bounty program on HackerOne, Bugcrowd or Intigriti, and no security address in the Trust Center. The only channels are the general contact form and the Jira Service Management customer portal. No Security pointer is emitted, because there is no disclosure surface to point at. This is the cheapest gap on this profile to close: a three-line RFC 9116 file at https://aiola.ai/.well-known/security.txt.