generated: '2026-08-09' method: searched probe: true description: >- Chili Piper publishes a vulnerability reporting process in the SECURITY.md of its official Chili-Piper/mcp-assets repository, with a named security mailbox and a stated response target. No /.well-known/security.txt (RFC 9116) is served on any Chili Piper host, and no public bug bounty program (HackerOne, Bugcrowd, Intigriti) was found. policy: - https://github.com/Chili-Piper/mcp-assets/blob/main/SECURITY.md contact: - security@chilipiper.com response_target: 48 hours disclosure_guidance: 'Report privately by email; do not open a public GitHub issue for security vulnerabilities.' bug_bounty: present: false platforms_checked: [HackerOne, Bugcrowd, Intigriti] security_txt: present: false probed: - {url: 'https://www.chilipiper.com/.well-known/security.txt', status: 404} evidence: - source: https://github.com/Chili-Piper/mcp-assets/blob/main/SECURITY.md kind: security-policy fetched: '2026-08-09' quote: 'Reporting a vulnerability ... Email: security@chilipiper.com ... We aim to respond within 48 hours.' scope_note: >- The published SECURITY.md scopes itself to the mcp-assets repository (skills and GPT configs). Chili Piper publishes no separate product-wide vulnerability disclosure policy at a well-known location; the corporate security posture is presented through the Vanta-hosted trust center. related: trust_center: security/chili-piper-trust-center.yml domain_security: security/chili-piper-domain-security.yml