generated: '2026-09-07' method: searched probe: true source: https://www.artillery.io/terms/security note: >- probe-security-programs.py returned vdp=none because Artillery serves no /.well-known/security.txt and does not use any of the conventional /security or /responsible-disclosure paths — its policy lives at /terms/security (mirrored at /security-policy). Found by following the "Security Policy" link in the site footer under "Legal & Compliance". policy: - https://www.artillery.io/terms/security - https://www.artillery.io/security-policy - https://github.com/artilleryio/artillery/blob/main/SECURITY.md contact: - security@artillery.io policy_last_revised: '2024-08-27' program: bug_bounty: false bounty_platform: null cve_assignment: true coordinated_disclosure: true acknowledgement_sla: 24 hours detailed_response_sla: 2 business days progress_updates: at least every 5 days (RFPolicy) embargo: typically 72 hours from CVE issue publication: advisory emailed to customers on the embargo date, published on the Artillery blog within 6 hours supported_versions_table: https://github.com/artilleryio/artillery/blob/main/SECURITY.md third_party_pentest: >- "Regular pentests conducted by a third-party security firm" — stated at https://www.artillery.io/docs/resources/security evidence: - source: https://www.artillery.io/terms/security kind: security-policy-page http_status: 200 keywords: [responsibly disclose, security@artillery.io, RFPolicy, CVE, embargo, disclosure policy] - source: https://github.com/artilleryio/artillery/blob/main/SECURITY.md kind: repo-security-policy http_status: 200 - source: https://www.artillery.io/docs/resources/security kind: security-overview http_status: 200 - source: https://www.artillery.io/.well-known/security.txt kind: security.txt http_status: 404 result: not served x-evidence: fetched: '2026-09-07'