generated: '2026-08-14' method: probed probe: true source: https://claw.bounti.ai/.well-known/security.txt policy: - https://bounti.ai/privacy-policy contact: - mailto:security@bounti.ai preferred_languages: [en] expires: '2027-04-01T00:00:00.000Z' bug_bounty: null evidence: - source: https://claw.bounti.ai/.well-known/security.txt kind: security.txt http_status: 200 content_type: text/plain; charset=utf-8 file: ../well-known/bounti-security.txt fetched: '2026-08-14' - source: https://bounti.ai/.well-known/security.txt kind: security.txt http_status: 404 fetched: '2026-08-14' notes: >- Bounti serves a valid RFC 9116 security.txt from the B.Claw application host (claw.bounti.ai) with a dedicated security@bounti.ai contact and an unexpired Expires field. Two gaps worth reporting to the provider: the file is NOT served from the apex bounti.ai (404), which is where most scanners and researchers look first; and the Policy field points at the general privacy policy rather than a dedicated vulnerability-disclosure policy. No bug-bounty program (HackerOne / Bugcrowd / Intigriti) was found. /security, /responsible-disclosure and /vulnerability-disclosure on bounti.ai all return 404.