generated: '2026-09-07' method: searched source: https://getelva.ai/security note: >- Corrected from the initial probe-security-programs.py output, which credited https://docs.getelva.ai/vulnerability-disclosure — that URL is an SPA shell soft-404 (the docs renderer answers 200 with the site chrome for unknown paths; the .md variant returns 404 "Section not found"). The real published disclosure channel is on the Elva security page: report to security@theneo.io (the program is operated by Theneo, Elva's parent), response within one business day, and "we credit every valid finding". Annual third-party penetration testing, summary shared under NDA. No security.txt is served on any Elva host (getelva.ai 404, probed 2026-09-07), and no public bug-bounty platform program (HackerOne/Bugcrowd/Intigriti) was found. contact: security@theneo.io response_time: one business day recognition: credits every valid finding bounty: none-published security_txt: false evidence: - url: https://getelva.ai/security http_status: 200 detail: '"Vulnerability disclosure: open — security@theneo.io, one business day response"' - url: https://getelva.ai/.well-known/security.txt http_status: 404