generated: '2026-08-10' method: searched probe: true source: https://buildops.com/security-policy policy: - https://buildops.com/security-policy contact: - security@buildops.com channels: - kind: email value: security@buildops.com published_on: - https://buildops.com/security-policy - https://trust.buildops.com/ instruction: >- The security policy directs readers with questions about security practices or a concern to report, to security@buildops.com. bug_bounty: present: false platform: null note: No HackerOne, Bugcrowd or Intigriti program found. security_txt: served: false probed: - {url: 'https://buildops.com/.well-known/security.txt', status: 404} - {url: 'https://developer.buildops.com/.well-known/security.txt', status: 404} evidence: - {source: 'https://buildops.com/security-policy', http_status: 200, kind: security-policy} - {source: 'https://trust.buildops.com/', http_status: 200, kind: trust-center} gaps: - >- A security contact is published but there is no formal responsible-disclosure or coordinated-vulnerability-disclosure policy: no scope statement, no safe harbour language, and no response-time commitment for reporters. - >- No RFC 9116 /.well-known/security.txt, so the contact is not machine discoverable. Serving one at buildops.com would take a single text file and would point at the policy page that already exists.