generated: '2026-07-19' method: searched probe: false source: https://facilio.com/security/ policy: [https://facilio.com/security/] contact: [security@facilio.com] bug_bounty: false response_time: 2 working days summary: >- Facilio operates a responsible disclosure process documented on its security page. Vulnerabilities are reported to security@facilio.com with a stated expected response time of two working days. No formal bug-bounty program (HackerOne/Bugcrowd/Intigriti) was found. Note: /.well-known/security.txt is not served (WAF returns 403), so this was captured from the security page, not an RFC 9116 file. evidence: - source: https://facilio.com/security/ kind: responsible-disclosure-page detail: 'Reports to security@facilio.com, expected response time of 2 working days'