generated: '2026-07-19' method: searched probe: true source: https://www.eye.security/.well-known/security.txt policy: - https://www.eye.security/responsible-disclosure-policy contact: - mailto:security@eye.security encryption: https://www.eye.security/hubfs/sec-pgp-key.txt preferred_languages: [en, nl, de] expires: '2027-05-01T00:00:00.000Z' bug_bounty: program: HackerOne type: VDP reward: swag (high/critical severity) acknowledgement_sla: 5 business days safe_harbor: true scope_note: >- In-scope assets are Eye-owned/managed internet-facing systems (agent.eye.security, api.control.eye.security, portal.eye.security and related infrastructure). Marketing sites (www.eye.security) and customer/third-party systems are out of scope. These are internal control-plane APIs; Eye Security publishes no public developer API. evidence: - source: https://www.eye.security/.well-known/security.txt kind: security.txt (live probe) - source: https://www.eye.security/responsible-disclosure-policy kind: responsible-disclosure page (HackerOne VDP, safe harbor)