generated: '2026-09-19' method: searched source: https://docs.algovoi.co.uk/security#coordinated-vulnerability-disclosure description: >- AlgoVoi runs a coordinated vulnerability disclosure process with a published contact, scope and response targets, but no paid bug bounty ("Not yet ... A formal paid bug bounty is on the roadmap" — security FAQ). Three hosts serve an RFC 9116 security.txt; the Policy URLs those files point at are both broken (a /AlgoVoi/compliance.html path that 404s and a GitHub INCIDENT_RESPONSE_PLAN.md that 404s), so the live policy text is the docs security page, which security.txt names in its Acknowledgments field. contact: email: security@algovoi.co.uk alternate: https://github.com/chopmob-cloud/AlgoVoi-Platform-Adapters/issues (non-sensitive only — "do not open a public GitHub issue" for security reports) languages: [en] security_txt: - {url: 'https://algovoi.co.uk/.well-known/security.txt', http_status: 200, expires: '2027-04-26T00:00:00Z', policy: 'https://algovoi.co.uk/AlgoVoi/compliance.html#disclosure', policy_status: 404, acknowledgments: 'https://docs.algovoi.co.uk/security', file: well-known/algovoi-co-uk-security.txt} - {url: 'https://api.algovoi.co.uk/.well-known/security.txt', http_status: 200, expires: '2027-04-19T00:00:00Z', policy: 'https://github.com/chopmob-cloud/AlgoVoi-Platform-Adapters/blob/master/compliance/INCIDENT_RESPONSE_PLAN.md', policy_status: 404, file: well-known/algovoi-co-uk-api-security.txt} - {url: 'https://cloud.algovoi.co.uk/.well-known/security.txt', http_status: 200, expires: '2027-04-19T00:00:00Z', policy: 'https://github.com/chopmob-cloud/AlgoVoi-Platform-Adapters/blob/master/compliance/INCIDENT_RESPONSE_PLAN.md', policy_status: 404, file: well-known/algovoi-co-uk-cloud-security.txt} policy: url: https://docs.algovoi.co.uk/security section: Coordinated vulnerability disclosure statement: '"We commit to acknowledging receipt within 2 business days, providing a triage classification within 5 business days, and a remediation timeline appropriate to severity." The apex security.txt comments state tighter targets: "Acknowledgement target: 1 business day. Triage outcome target: 3 business days."' scope: in: ['*.algovoi.co.uk (operational subdomains)'] out: [Customer-controlled wallets, Public on-chain data, Third-party services AlgoVoi depends on] safe_harbour: not stated disclosure_window: '"Please give us a reasonable time to respond before public disclosure." (security.txt)' bug_bounty: program: none statement: '"Do you have a bug bounty programme? Not yet. We accept coordinated disclosure via security@algovoi.co.uk and follow the policy in our security.txt. A formal paid bug bounty is on the roadmap"' platforms_checked: [hackerone, bugcrowd, intigriti] platforms_result: none found response_targets: acknowledgement: 2 business days (docs) / 1 business day (security.txt) triage: 5 business days (docs) / 3 business days (security.txt) support_page: '"Security disclosure (security@) — Acknowledged within 24 hours" (https://docs.algovoi.co.uk/support)' related: agent_vulnerability_disclosure: 'https://agent-trust-bench.algovoi.co.uk/disclosure-policy — a separate AVD policy for findings the Agent Trust Bench makes about third-party agent stacks (30-day private notice, publication thresholds); not a program for reporting AlgoVoi''s own vulnerabilities.' penetration_testing: '"annual external pentest scheduled for Q4 2026"; self-conducted external audit 2026-05-27 published on the security page.' evidence: - {url: 'https://docs.algovoi.co.uk/security.md', http_status: 200, fetched: '2026-09-19'} - {url: 'https://docs.algovoi.co.uk/support.md', http_status: 200, fetched: '2026-09-19'} - {url: 'https://algovoi.co.uk/.well-known/security.txt', http_status: 200, fetched: '2026-09-19'} - {url: 'https://algovoi.co.uk/AlgoVoi/compliance.html', http_status: 404, fetched: '2026-09-19', note: 'the security.txt Policy target; https://algovoi.co.uk/compliance.html (no /AlgoVoi/ prefix) is 200'} - {url: 'https://github.com/chopmob-cloud/AlgoVoi-Platform-Adapters/blob/master/compliance/INCIDENT_RESPONSE_PLAN.md', http_status: 404, fetched: '2026-09-19'}