generated: '2026-08-14' method: searched probe: true source: https://github.com/abdulrahimiqbal/dreamthreads-developer/blob/main/SECURITY.md policy: - https://github.com/abdulrahimiqbal/dreamthreads-developer/blob/main/SECURITY.md contact: - rahim@mydreamthreads.xyz bug_bounty: program: null platform: null note: No HackerOne, Bugcrowd or Intigriti program found. security_txt: served: false probed: - url: https://mydreamthreads.xyz/.well-known/security.txt status: 404 disclosure_policy: summary: >- A SECURITY.md in the provider's public developer toolkit repository instructs reporters not to open a public issue for a vulnerability, credential, private dream, or other sensitive data, and to report privately to rahim@mydreamthreads.xyz with the affected endpoint, expected impact, and a minimal reproduction that contains no real dream text or personal information. key_compromise: >- "Partner keys must stay in a server-side secret manager. If a key may have been exposed, stop using it and request rotation immediately." disclosure_window: not stated safe_harbour: not stated evidence: - source: https://raw.githubusercontent.com/abdulrahimiqbal/dreamthreads-developer/HEAD/SECURITY.md kind: security-policy http_status: 200 keywords: [security, vulnerability, report, credential, rotation] - source: https://mydreamthreads.xyz/.well-known/security.txt kind: security.txt http_status: 404 - source: https://mydreamthreads.xyz/security kind: disclosure-page http_status: 404 note: >- The provider's automated probe found nothing because the policy is not on the marketing domain — it lives in the GitHub developer toolkit that the site, llms.txt and apis.json all link to. It is a real, first-party, publicly readable disclosure policy with a named private contact, so a Security pointer is warranted; a security.txt at the API host would make it machine-discoverable.