generated: '2026-08-06' method: searched probe: true source: https://www.aristamd.com/security/ policy: [https://www.aristamd.com/security/] contact: [info@aristamd.com] security_txt: false summary: >- AristaMD publishes a security posture page that names an address for reporting a potential security issue. It does not run a coordinated vulnerability disclosure program: there is no policy document, no safe-harbour statement, no response-time commitment, no scope definition, no bug bounty and no RFC 9116 security.txt. reporting: channel: email address: info@aristamd.com verbatim: >- "If you have any questions, comments or concerns or if you wish to report a potential security issue, please contact info@aristamd.com" dedicated_security_alias: false note: >- The address is the general company inbox, not a security@ alias. A researcher has no signal that a report will reach a security owner. not_found: - {item: 'security.txt (RFC 9116)', probed: 'https://www.aristamd.com/.well-known/security.txt', status: 404} - {item: 'security.txt on the API host', probed: 'https://api.aristamd.com/.well-known/security.txt', status: 404} - {item: root security.txt, probed: 'https://www.aristamd.com/security.txt', status: 404} - {item: bug bounty program, searched: [HackerOne, Bugcrowd, Intigriti], result: none} - {item: responsible/coordinated disclosure policy page, probed: 'https://www.aristamd.com/legal/', status: 404} - {item: safe harbour statement, result: none} - {item: response-time or triage commitment, result: none} - {item: in-scope/out-of-scope definition, result: none} - {item: PGP key or encrypted reporting channel, result: none} remedy: >- The lowest-cost fix is an RFC 9116 security.txt at https://www.aristamd.com/.well-known/security.txt with Contact, Policy, Preferred-Languages and Expires. A security@aristamd.com alias and a short safe-harbour statement would follow. For a company processing US protected health information, the absence of a named disclosure route is the more material gap of the two. evidence: - source: https://www.aristamd.com/security/ kind: disclosure page status: 200 keywords: [vulnerability, security issue, report, incident response] x-evidence: fetched: '2026-08-06'