generated: '2026-07-19' method: searched probe: true source: well-known/eye-security-security.txt program_type: vulnerability-disclosure-program platform: HackerOne policy: - https://www.eye.security/responsible-disclosure-policy contact: - mailto:security@eye.security encryption: https://www.eye.security/hubfs/sec-pgp-key.txt preferred_languages: - en - nl - de security_txt_expires: '2027-05-01T00:00:00.000Z' safe_harbor: true acknowledgment_sla: within 5 business days recognition: exclusive Eye swag for high and critical severity vulnerabilities scope_in: - Eye-owned internet-accessible systems (e.g. agent.eye.security, portal.eye.security) - Eye-owned IP ranges and self-hosted infrastructure scope_out: - Marketing websites - Customer systems - Third-party SaaS platforms - CSRF without demonstrated impact - Missing security headers - Open redirects - Self-XSS - Email/DNS policy misconfigurations without impact evidence: - source: well-known/eye-security-security.txt kind: security.txt (previously harvested) - source: https://www.eye.security/responsible-disclosure-policy kind: responsible-disclosure-policy (HackerOne VDP, safe harbor)