generated: '2026-08-13' method: searched source: https://www.didomi.io/security info: name: Didomi vulnerability disclosure provider: didomi description: >- Didomi publishes a named security contact and an explicit invitation to security researchers, in prose, on its security page. It does NOT run a public bug bounty and does NOT serve a machine-readable security.txt. checked: '2026-08-13' program: exists: true type: security-contact bug_bounty: false platform: null contact: security@didomi.io policy_url: https://www.didomi.io/security policy_text: >- "If you are a security researcher who has potentially discovered a security weakness or vulnerability in Didomi's systems, please send an email to security@didomi.io" safe_harbor: not stated scope: not published response_sla: not published rewards: none published pgp_key: null evidence: - url: https://www.didomi.io/security http_status: 200 finding: >- Security contact security@didomi.io published, alongside an ISO/IEC 27001:2022 certification claim and a description of Didomi's ISMS practices (annual policy review, internal and access audits, vendor security management, DDoS mitigation, encryption, intrusion detection, penetration testing, vulnerability scanning, geographically separated datacenters, background checks, mandatory security training). fetched: '2026-08-13' - url: https://didomi.io/.well-known/security.txt http_status: 404 finding: No RFC 9116 security.txt served on the apex. - url: https://api.didomi.io/.well-known/security.txt http_status: 404 finding: No RFC 9116 security.txt served on the API host. - url: https://www.didomi.io/security.txt http_status: 404 finding: No security.txt at the legacy root path either. - url: https://github.com/didomi/security http_status: 200 finding: >- A public repo named "security" exists ("Security information for the Didomi platform") but its README is two lines and carries no policy — last pushed 2021-10-21. - url: https://trust.didomi.io http_status: 200 finding: >- A Vanta-hosted trust center is served, but it renders client-side and exposed no disclosure policy to an anonymous fetch. searched_and_absent: - platform: HackerOne result: no Didomi program found - platform: Bugcrowd result: no Didomi program found - platform: Intigriti result: no Didomi program found remediation: - >- Publish /.well-known/security.txt on didomi.io AND api.didomi.io per RFC 9116, with Contact: mailto:security@didomi.io, a Policy: URL, Expires:, and Preferred-Languages:. The contact already exists — only the machine-readable file is missing, which makes this the cheapest security-posture improvement available to Didomi. - Publish scope and safe-harbour terms alongside the contact.