generated: '2026-09-02' method: searched source: https://ambientmesh.io/docs/operations/solo-builds/ provider: Ambient Mesh providerId: ambient-mesh description: >- Vulnerability disclosure routes for Ambient Mesh, read from the provider's own documentation. probe-security-programs.py found nothing automatically (vdp=none, trust=none) because there is no /.well-known/security.txt and no bug-bounty listing; the disclosure contact is stated in prose on the Solo builds page instead. security_txt: present: false probed: https://ambientmesh.io/.well-known/security.txt status: 404 contacts: - type: email value: security@solo.io scope: Solo.io builds of Istio (the distribution ambientmesh.io documents) quote: >- "To report a security vulnerability, email security@solo.io with the vulnerability details." source: https://ambientmesh.io/docs/operations/solo-builds/ - type: support value: https://www.solo.io/istio-support scope: bug reports for Solo builds of Istio quote: 'To report a bug, contact the Solo support team.' source: https://ambientmesh.io/docs/operations/solo-builds/ - type: policy value: https://github.com/istio/istio/blob/master/.github/SECURITY.md scope: the upstream Istio project status: 200 note: >- Already wired in apis.yml as type SecurityPolicy. Governs the open-source components (istiod, istio-cni, ztunnel) that Ambient Mesh is built from. bug_bounty: present: false platforms_checked: - HackerOne - Bugcrowd - Intigriti note: no program found for ambientmesh.io disclosure_policy: published_by_provider: false note: >- ambientmesh.io states a disclosure CONTACT but publishes no disclosure policy of its own (no stated response SLA, safe-harbour clause or scope document). The upstream Istio SECURITY.md is the nearest published policy. trust_center: present: false note: >- No trust center and no named certifications on ambientmesh.io, so no TrustCenter or Compliance pointer is emitted. Enterprise compliance material for the commercial distribution lives on solo.io, a separate catalog entry.