generated: '2026-09-14' method: searched probe: true source: https://support.avaya.com/css/public/documents/100045520 policy: - https://support.avaya.com/css/public/documents/100045520 contact: - securityalerts@avaya.com advisories: https://support.avaya.com/security bug_bounty: null detail: >- Avaya runs a named Product Security Vulnerability Response Policy. Independent security researchers are directed to securityalerts@avaya.com; customers and business partners report through the standard support process. Avaya Security Advisories (ASAs) are published on the support site, with the policy stating notification typically within 24 hours of a vulnerability's release. There is no public bug bounty on HackerOne, Bugcrowd or Intigriti, and — notably for a company of this size — no /.well-known/security.txt on any Avaya host, so the program is discoverable only by reading the support site. evidence: - {source: 'https://support.avaya.com/css/public/documents/100045520', status: 200, kind: policy-document} - {source: 'https://support.avaya.com/security', status: 200, kind: advisory-index} - {source: 'https://www.avaya.com/en/trust-center/security/portfolio-security/', status: 200, kind: security-by-design-page} - {source: '/.well-known/security.txt on avaya.com, www.avaya.com, support.avaya.com', status: 404, kind: absent}