generated: '2026-09-19' method: searched probe: true source: https://councilof.ai/.well-known/security.txt policy: - https://councilof.ai/firewall-charter contact: - mailto:nicholas@csoai.org evidence: - source: https://councilof.ai/.well-known/security.txt kind: security.txt (live probe) note: 'security.txt is a real RFC 9116 document (Contact mailto:nicholas@csoai.org, Expires 2027-08-19, Canonical, Preferred-Languages en) served on councilof.ai and, with a shorter Expires, on csoai.org. The Policy URL it names (https://councilof.ai/firewall-charter) is the ''Measurement/Remediation Firewall Charter'' — a published auditor-independence commitment (the measurer never operates the fixer), NOT a vulnerability-disclosure policy: it states no scope, safe-harbour or response time for security reports. The /security page is ''temporarily withdrawn''. No bug-bounty programme (HackerOne/Bugcrowd/Intigriti) was found. What exists is a disclosure CONTACT, verified live; recorded as such.' channels: - kind: email value: nicholas@csoai.org source: security.txt Contact policy_kind: independence charter (not a VDP) bug_bounty: null files: - well-known/councilof-ai-security.txt - well-known/councilof-ai-csoai-org-security.txt