generated: '2026-09-19' method: searched probe: true source: well-known/dynamicfeed-ai-security.txt (https://dynamicfeed.ai/.well-known/security.txt, HTTP 200) and https://dynamicfeed.ai/security/advisories (HTTP 200) policy_url: https://dynamicfeed.ai/terms policy_http_status: 200 summary: 'Dynamic Feed publishes an RFC 9116 security.txt with a contact address and a public security-advisories page with a machine-readable key-lifecycle registry, but NO written vulnerability-disclosure policy: the security.txt Policy field points at the Terms of Service, whose only relevant clause is "Do not attempt to circumvent rate limits, authentication, or security controls." There is no bug bounty (no HackerOne, Bugcrowd or Intigriti program was found) and no safe-harbour statement.' contact: - mailto:hello@dynamicfeed.ai security_txt: hosts: - host: dynamicfeed.ai url: https://dynamicfeed.ai/.well-known/security.txt status: 200 file: well-known/dynamicfeed-ai-security.txt legacy_path: https://dynamicfeed.ai/security.txt (200, identical) fields: contact: mailto:hello@dynamicfeed.ai expires: '2027-06-03T00:00:00.000Z' preferred_languages: en canonical: https://dynamicfeed.ai/.well-known/security.txt policy: https://dynamicfeed.ai/terms missing_fields: - Encryption - Acknowledgments - Hiring signed: false advisories: url: https://dynamicfeed.ai/security/advisories status: 200 published: - id: DF-SA-2026-001 date: '2026-07-11' title: Production signing-key rotation after private credential exposure state: resolved integrator_action: stop accepting key df-ed25519-4cb32e72f333; upgrade verifiers to lifecycle-enforcing versions machine_readable: https://dynamicfeed.ai/.well-known/signing-key-registry.json note: Same-day public disclosure with root-cause detail, affected-package table and a conservative compromise boundary — a strong incident-transparency signal even though no disclosure POLICY exists. bug_bounty: present: false platforms_checked: - HackerOne - Bugcrowd - Intigriti - provider site safe_harbor: false evidence: - source: well-known/dynamicfeed-ai-security.txt kind: security.txt (harvested 2026-09-19) - source: https://dynamicfeed.ai/security/advisories kind: advisory page (HTTP 200) - source: https://dynamicfeed.ai/terms kind: Policy target; a ToS, not a VDP