generated: '2026-09-05' method: searched probe: true source: https://www.cequence.ai/responsible-disclosure-policy/ policy: - https://www.cequence.ai/responsible-disclosure-policy/ contact: - security@cequence.ai bug_bounty: operates: false statement: >- "Please note that Cequence does not operate a bug bounty program and we do not offer reward nor compensation in exchange for the identification of potential issues." — verbatim from the published policy. safe_harbor: >- "By responsibly submitting your findings to Cequence Security in accordance with these guidelines Cequence Security agrees not to pursue legal action against you." acknowledgement_sla: within three business days of submission submission: channel: email address: security@cequence.ai required_content: >- A detailed summary of the vulnerability including target, steps, tools and artifacts used during discovery; screen captures welcome. security_txt: served: false probed: '2026-09-05' note: >- /.well-known/security.txt returns 404 on www.cequence.ai, aigateway.cequence.ai (SPA shell), mcp.aigateway.cequence.ai and helpdesk.cequence.ai. The policy and the contact address both exist and are stable — an RFC 9116 file would make them machine-discoverable at zero cost. The security contact IS already published in DNS: the cequence.ai CAA record carries 0 iodef "mailto:security@cequence.ai". evidence: - source: https://www.cequence.ai/responsible-disclosure-policy/ kind: disclosure-policy http_status: 200 fetched: '2026-09-05' - source: cequence.ai CAA record kind: iodef value: 0 iodef "mailto:security@cequence.ai"