generated: '2026-09-18' method: searched source: https://www.usebruno.com/security provider: Bruno providerId: bruno-api description: >- Bruno publishes a security program page naming a security contact and describing its incident response, access control, secure development and vendor review practices. It is a security contact and program disclosure, not a formal coordinated-disclosure policy: no response window, safe-harbour language or bug bounty is published, and no RFC 9116 security.txt is served on any Bruno host. disclosure: published: true url: https://www.usebruno.com/security http_status: 200 contact_email: security@usebruno.com contact_evidence: 'Contact Our Security Team - "If you have any questions, reach out to us at security@usebruno.com"' policy_document: false response_sla: null safe_harbour: null security_txt: served: false probed: - url: https://www.usebruno.com/.well-known/security.txt status: 404 - url: https://usebruno.com/.well-known/security.txt status: 404 - url: https://docs.usebruno.com/.well-known/security.txt status: 404 bug_bounty: published: false programs_checked: [HackerOne, Bugcrowd, Intigriti] note: No bug bounty or vulnerability disclosure program was found for Bruno on the common platforms or on its own site. github: security_md: false probed: url: https://raw.githubusercontent.com/usebruno/bruno/main/SECURITY.md status: 404 note: >- The usebruno/bruno repository publishes no SECURITY.md; GitHub private vulnerability reporting may still be enabled, which this probe cannot observe. practices_published: - Role-based access control and multi-factor authentication on internal systems. - Code reviews and dependency audits following OWASP principles. - A documented incident response plan for vulnerabilities and breaches. - Third-party vendor security checks and contractual data protection review. related: trust_center: security/bruno-api-trust-center.yml domain_security: security/bruno-api-domain-security.yml maintainers: - FN: Kin Lane email: kin@apievangelist.com