generated: '2026-07-19' method: searched probe: true source: https://exe.dev/security policy: [https://exe.dev/security] contact: [security@exe.dev] bug_bounty: false bug_bounty_note: exe.dev does not run a paid bug-bounty program. security_bulletins: https://exe.dev/security evidence: - {source: https://exe.dev/security, kind: security-page, detail: "Reports to security@exe.dev; public security-bulletin feed of disclosed vulnerabilities (e.g. 2026-02-25 medium-severity VM-sharing port-exposure fix)."} notes: >- No /.well-known/security.txt is published (404). Disclosure contact and a running security-bulletin feed are published on the /security page.