generated: '2026-09-06' method: probed source: live probes of the Eden AI web and API surface published: false description: >- Eden AI publishes no vulnerability disclosure policy, no security.txt, and no bug bounty program that could be found from its own surface. This file records a checked absence, not a finding against the company's security posture — the trust center documents independent penetration testing and a documented incident-response process (security/eden-ai-trust-center.yml). What is missing is the PUBLIC INTAKE PATH a researcher would use. No `Security` pointer is emitted. probes: - {url: 'https://edenai.co/.well-known/security.txt', status: 404} - {url: 'https://www.edenai.co/.well-known/security.txt', status: 404} - {url: 'https://api.edenai.run/.well-known/security.txt', status: 404} - {url: 'https://api.eu.edenai.run/.well-known/security.txt', status: 404} - {url: 'https://mcp.edenai.run/.well-known/security.txt', status: 404} - {url: 'https://app.edenai.run/.well-known/security.txt', status: 404} - {url: 'https://www.edenai.co/responsible-disclosure', status: 404} - {url: 'https://www.edenai.co/vulnerability-disclosure', status: 404} - {url: 'https://www.edenai.co/security', status: 200, note: 'Marketing security page — no disclosure policy, no security contact, no reporting instructions.'} - {url: 'https://trust.edenai.co/', status: 200, note: 'Trust center — controls and certifications; no researcher intake path.'} bug_bounty: platform: null checked: [HackerOne, Bugcrowd, Intigriti] found: false contact_of_last_resort: email: support@edenai.co note: >- The only published address is general support (documented for GDPR data-subject requests). It is NOT advertised as a security contact, so it is recorded as a fallback rather than as a disclosure channel. checked: '2026-09-06'