generated: '2026-09-13' method: searched source: https://buf.build/docs/contact/ docs: https://buf.build/docs/contact/ program: published: true type: email disclosure channel contact: security@buf.build statement: 'For security disclosures, email security@buf.build.' evidence: - url: https://buf.build/docs/contact/ status: 200 quote: 'For security disclosures, email security@buf.build.' channels: - kind: security disclosure value: security@buf.build - kind: product support value: support@buf.build - kind: sales and general value: https://buf.build/contact - kind: open-source issues value: 'GitHub issues on the relevant bufbuild repository' - kind: community value: 'https://buf.build/b/slack — explicitly community discussion, NOT production support' not_found: security_txt: path: /.well-known/security.txt hosts_probed: [buf.build, www.buf.build, api.buf.build, docs.buf.build] result: >- absent. buf.build returns its SPA shell (soft-404) and api.buf.build returns a plain 404. No RFC 9116 file is served anywhere on the estate. bug_bounty: result: 'none found — no HackerOne, Bugcrowd or Intigriti program surfaced.' disclosure_policy_page: result: 'none found — no /security or /security-policy page; both return the SPA shell.' trust_center: result: 'none — trust.buf.build and security.buf.build do not resolve (NXDOMAIN).' gap: >- Buf publishes a working security contact but nothing machine-readable: no security.txt, no disclosure policy, no stated response SLA or safe-harbour language. Adding an RFC 9116 file naming security@buf.build would be a one-file fix.