generated: '2026-08-06' method: searched source: https://akuity.io/security-compliance description: >- Akuity runs a stated responsible-disclosure program with a named security contact, published on its Security and Compliance page. It does NOT publish an RFC 9116 security.txt, a bug-bounty program, or a dedicated disclosure policy page with scope and safe-harbour terms. program: exists: true type: responsible-disclosure statement: >- "Akuity encourages responsible disclosure of security vulnerabilities. Security contact: security@akuity.io. Reported issues are reviewed, triaged, and addressed according to internal procedures." policy_page: https://akuity.io/security-compliance contact: - mailto:security@akuity.io - mailto:security+ssl@akuity.io # CAA iodef record on akuity.cloud bug_bounty: exists: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] security_txt: exists: false probes: - url: https://akuity.io/.well-known/security.txt status: 404 - url: https://akuity.io/security.txt status: 404 - url: https://akuity.cloud/.well-known/security.txt status: 404 - url: https://docs.akuity.io/.well-known/security.txt status: 404 - url: https://trust.akuity.io/.well-known/security.txt status: 200 verdict: false-positive note: Vanta SPA catch-all — control path returned identical HTML with 200. - url: https://status.akuity.io/.well-known/security.txt status: 200 verdict: vendor-not-provider note: 'Atlassian Statuspage''s own file; Canonical: https://www.atlassian.com/.well-known/security.txt' checked: '2026-08-06' vulnerability_management: source: https://akuity.io/security-compliance practices: - Regular vulnerability scanning of public-facing assets - Risk-based remediation timelines - Periodic third-party penetration testing - Verification and tracking of remediation efforts - Dependency scanning and vulnerability detection in CI/CD customer_sla: >- "CVE notifications and SLA on resolution" is an Enterprise-plan feature — a contractual remediation SLA, not a published one. supply_chain: signed_images: https://docs.akuity.io/akuity-portal/security/verifying-images distroless_report: https://docs.akuity.io/akuity-portal/security/distroless_report incident_response: documented: true statement: >- "Documented incident response plan. Defined escalation and communication procedures. Customers are notified of security incidents in accordance with contractual and regulatory obligations." gap: note: >- A one-line email contact on a marketing-adjacent page is the weakest form of a disclosure program. Publishing an RFC 9116 /.well-known/security.txt on akuity.io and akuity.cloud — pointing at that same security@akuity.io and a policy page with scope and safe-harbour terms — would be a small change with a real effect on how quickly a researcher reaches the right team. evidence: - source: https://akuity.io/security-compliance kind: published responsible-disclosure statement fetched: '2026-08-06' http_status: 200 - source: dig CAA akuity.cloud kind: 'CAA iodef record: 0 iodef "mailto:security+ssl@akuity.io"' fetched: '2026-08-06'