generated: '2026-08-02' method: searched probe: true source: https://www.bigeye.com/platform/security url: https://www.bigeye.com/platform/security contact: - security@bigeye.com policy: [] bug_bounty: program: null platform: null note: >- No bug bounty program was found on HackerOne, Bugcrowd or Intigriti, and none is referenced on Bigeye's site or documentation. formal_disclosure_policy: false formal_disclosure_policy_note: >- Bigeye publishes a named security contact and describes its vulnerability management practices, but does not publish a formal responsible-disclosure or coordinated-vulnerability-disclosure policy with scope, safe harbour and response commitments. Recorded honestly: a reachable security contact exists, a published VDP does not. security_txt: present: false probed: - {url: 'https://www.bigeye.com/.well-known/security.txt', status: 404} - {url: 'https://docs.bigeye.com/.well-known/security.txt', status: 404} - {url: 'https://mcpgateway.bigeye.com/.well-known/security.txt', status: 404} - {url: 'https://app.bigeye.com/.well-known/security.txt', status: 200 (rejected — SPA HTML catch-all, not RFC 9116 text)} recommendation: Publishing an RFC 9116 /.well-known/security.txt pointing at security@bigeye.com would be a one-file fix. practices_published: source: https://docs.bigeye.com/docs/security-and-compliance items: - {practice: vulnerability scanning, detail: Code review and dependency vulnerability scans as part of the software engineering process.} - {practice: penetration testing, detail: Annual third-party penetration test over the application layers; reports available on demand.} - {practice: web application firewall, detail: AWS WAF Security Automation.} - {practice: security incident notification, detail: Customers notified without undue delay by email, or by phone if email is unavailable.} - {practice: security training, detail: Privacy and security training at onboarding and annually thereafter, with electronic acknowledgement.} - {practice: access restriction, detail: Only the Information Security Team and CTO can access customer data during incident response.} evidence: - source: https://www.bigeye.com/platform/security kind: security page quote: Security inquiries — Have a question about our security practices? Reach out to our security team at security@bigeye.com fetched: '2026-08-02' http_status: 200 - source: https://docs.bigeye.com/docs/security-and-compliance kind: security practices documentation fetched: '2026-08-02' http_status: 200