generated: '2026-08-30' method: probed source: https://hackerone.com/akamai description: Akamai runs a vulnerability disclosure program on HackerOne. The program page resolves; a control request for a non-existent HackerOne handle returns 404, so the 200 is a real program page rather than a catch-all. Akamai's own security pages could not be read - www.akamai.com answers 403 to this crawler on every path - so the program terms, scope and safe-harbour language are not captured here. programs: - platform: HackerOne url: https://hackerone.com/akamai status: 200 type: vulnerability-disclosure control: url: https://hackerone.com/this-program-does-not-exist-zzz9 status: 404 note: Page body is a HackerOne SPA shell carrying the Akamai program title; scope and bounty terms not read. security_txt: served: false probes: - url: https://www.akamai.com/.well-known/security.txt status: 403 - url: https://techdocs.akamai.com/.well-known/security.txt status: 200 note: HTML documentation shell, not an RFC 9116 document. - url: https://developers.akamai.com/.well-known/security.txt status: 404 security_research: url: https://github.com/akamai/akamai-security-research status: 200 note: Akamai publishes its own offensive-security research and IoCs on GitHub (540 stars) - adjacent to, not the same as, a disclosure program. maintainers: - FN: Kin Lane email: kin@apievangelist.com