generated: '2026-09-04' method: searched source: https://appomni.com/ao-labs-vulnerability-disclosure-policy/ program: type: responsible-disclosure-policy name: AppOmni Responsible Disclosure Policy url: https://appomni.com/ao-labs-vulnerability-disclosure-policy/ status: 200 published: true publisher: AO Labs (AppOmni's security research team) summary: >- A published responsible-disclosure policy governing how AppOmni, through AO Labs, discloses vulnerabilities and misconfigurations it finds in third-party SaaS applications. It draws an explicit distinction between a vulnerability (a vendor-side flaw only the vendor can fix) and a misconfiguration (a customer-controllable setting), because the two follow different disclosure paths. embargo_window: 90 days from vendor notification before public disclosure process: >- AppOmni notifies the affected vendor immediately with technical details through that vendor's official disclosure channels, then withholds public disclosure for 90 days to allow investigation and remediation. direction: outbound direction_note: >- This policy describes how AppOmni discloses TO other vendors. It is a published security-disclosure posture, and it is the only such document AppOmni publishes. security_txt: served: false note: >- /.well-known/security.txt is 404 on appomni.com and api.appomni.com. status.appomni.com serves one, but it is Atlassian's (Canonical: https://www.atlassian.com/.well-known/security.txt), because that host is Atlassian Statuspage — it is not AppOmni's document. See well-known/appomni-well-known.yml. bug_bounty: program: null note: >- No HackerOne, Bugcrowd or Intigriti programme was found for AppOmni. Inbound vulnerability reports are directed through https://appomni.com/contact-us/ and https://appomni.com/support/. evidence: - url: https://appomni.com/ao-labs-vulnerability-disclosure-policy/ status: 200 - url: https://appomni.com/.well-known/security.txt status: 404 - url: https://api.appomni.com/.well-known/security.txt status: 404