generated: '2026-08-12' method: searched source: https://www.mozilla.org/.well-known/security.txt scope: operator-wide scope_note: >- Anonym publishes no product-specific vulnerability disclosure policy. Its entire public web surface is operated by Mozilla — anonymco.com wildcard-redirects to https://www.mozilla.org/en-US/anonym/ — so the applicable disclosure program is Mozilla's, served from the same host that serves the Anonym product pages. Recorded at operator scope, not claimed as an Anonym-branded program. program_present: true security_txt: url: https://www.mozilla.org/.well-known/security.txt status: 200 contact: security@mozilla.org policy: https://www.mozilla.org/en-US/security/ bounty: https://www.mozilla.org/en-US/security/bug-bounty/ bug_bounty: present: true name: Mozilla Security Bug Bounty Program url: https://www.mozilla.org/en-US/security/bug-bounty/ platform: self-hosted (Bugzilla) anonym_hosts_probed: - url: https://anonymco.com/.well-known/security.txt status: 200 document: false note: soft-200, wildcard redirect returns the Anonym marketing page, not a security.txt - url: https://anonymportal.com/.well-known/security.txt status: 200 document: false note: soft-200, Angular SPA catch-all returns index.html privacy_contacts: privacy: privacy@anonymco.com data_protection_officer: dpo@anonymco.com source: https://www.mozilla.org/en-US/anonym/privacy-policy/