generated: '2026-09-06' method: searched source: https://github.com/asyncapi/.github/blob/master/SECURITY.md probe: true note: >- The automated probe (probe-security-programs.py) found nothing, because asyncapi.com serves no /security page and no /.well-known/security.txt. The policy is real but it lives in the org-wide GitHub .github repository, which is where a Linux Foundation project normally publishes it — fetched and read on 2026-09-06. policy: - https://github.com/asyncapi/.github/blob/master/SECURITY.md contact: - security@asyncapi.com - https://github.com/asyncapi/asyncapi/security/advisories/new model: coordinated-vulnerability-disclosure bug_bounty: false commitments: acknowledgement: within 72 hours initial_assessment: within 5 business days reproduction: within 5 working days severity_bands: [critical, high, medium, low] security_txt: false evidence: - source: https://raw.githubusercontent.com/asyncapi/.github/master/SECURITY.md kind: security-policy http_status: 200 fetched: '2026-09-06' - source: https://www.asyncapi.com/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-09-06' - source: https://www.asyncapi.com/security kind: disclosure-page http_status: 404 fetched: '2026-09-06'